Broad-Based Black Economic Empowerment Act (B-BBEE Act)
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Documents available on tender detail page
Tender Type
Request for Bid(Open-Tender)
Delivery Location
40 Heronmere road - Reuven - Johannesburg - 2016
Organization Type
GOVERNMENT
Published
09 Sept 2026
OCDS Reference
ocds-9t57fa-169676
Date & Time
Thursday, 15 October 2026 - 11:00
Continue with tenders sharing this issuer, category, or province.
Return to this tender’s issuing organisation, province, or category.
Continue with tenders sharing this issuer, category, or province.
Venue
null
Enterprise owned by black people with at least 51% shareholding • 51% black people ownership = 5 points • less than 51% black women ownership = 0 points provide a valid and certified copy (not older than three (3) months) of BEE certificate / sworn affidavit, consolidated b-bbee certificate from verification agency if bidder is jv/consortium and certified copies (not older than three (3) months of ID copies of owners) 5
Categories
Request for Bid(Open-Tender)
40 Heronmere road - Reuven - Johannesburg - 2016
Tenders in this industry often require registration with these bodies.
Recommended Certifications
Having these can improve your winning chances: SAIDSA Accreditation, ISO 18788 (Security Operations Management)
AI Document Analysis Stages
Important Dates
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)09 Sept
2026
Tender Published
Tender was published
15 Oct
2026
Closing Date
Tender closing date
These references help suppliers understand the public-procurement framework around this opportunity. They are generated from the tender category, issuing organisation type and procurement context.
These rules commonly apply to South African public-sector procurement.
Act 53 of 2003
Provides the empowerment-compliance context often used in public-sector supplier evaluation.
Relevant because this is a South African public-sector procurement opportunity.
Act 108 of 1996 (s217)
This is general procurement context, not legal advice. Always verify requirements in the official tender documents and issuing authority notices.
Bid Advert Template-CYBER SECURITY (002).pdf
Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf
CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf
To download these documents and access AI-powered analysis, visit the main tender page.
Matched by category & region
Free guidance to prepare before you bid
Not sure if your business is ready for this tender? Check CSD, CIDB, and B-BBEE requirements, run a readiness assessment, and move from opportunity to submission.
Open Supplier Readiness HubMedian Estimate
R 1 137 583
Range
Based on 19 comparable awarded tenders. Companies with similar profiles typically bid near the median.
* Estimates are based on historical data and do not guarantee actual award values.
We refine every tender document through these stages so you can brief your team and prepare your bid with confidence. Anything marked as "in progress" will be upgraded automatically — no action required from you.
{"closingDate":"15 October 2026","closingTime":"11h00"}
Contact Information
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER){"name":"Zandile Mshweshwe","email":"[email protected]","phone":"011 490 7838","department":"SCM PERSON ZANDILE MSHWESHWE","address":"NTACT PERSON ZANDILE MSHWESHWE NUMBER 011 490 7838"}
Submission Guidelines
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)Returnable Documents: 1.1 INVITATION TO BID ( MBD 1 ), 1.3 CIDB STANDARD CONDITION OF TENDER, 2.2 FIRM PRICES FORM (MBD 3.1), 2.3 NON-FIRM PRICES FORM (MBD 3.2), 3.3 FORMAL CONTRACT (MBD 7.1), in arrears for more than 90 days & not older than 3 months or Lease agreement must be duly signed,
Evaluation Criteria
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)Pt−Pmin
Ps= 80 (1− Pmin)
Where
Ps = Points scored for comparative price of tender or offer under consideration;
Pt = Comparative price of tender or offer under consideration; and
Pmin = Comparative price of lowest acceptable tender or offer.
Table 1: Specific goals for the tender and points claimed are indicated per the table below.
(Note to organs of state: Where either the 90/10 or 80/20 preference point system is applicable,
corresponding points must also be indicated as such.
Note to tenderers: The tenderer must indicate how they claim points for each preference point system):
of 78
Number of Number of Number of Number of
points points points claimed points
allocated allocated (90/10 system) claimed
The specific goals allocated points in (90/10 system) (80/20 system) (To be (80/20
terms of this tender (To be (To be completed by system)
completed by completed by the tenderer) (To be
the organ of the organ of completed by
state) state) the tenderer)
Enterprise owned by black people with
at least with 51% shareholding
Enterprise owned by black youth with
at least 51% shareholding
Local suppliers within City
of Johannesburg Geographical area 10
F3.13.1 Tenders will only be accepted if:
a) The tenderer has in his or her possession an original valid tax clearance certificate or pin issued by the
South African Revenue Services or a pin
b) The tenderer is registered with Central System Database (CSD)
c) The tenderer is not in arrears for more than 3 months with municipal rates and taxes and municipal
service charges
d) The tenderer or any of its directors is not listed on the Register of Tender Defaulters in terms of the
Prevention and Combating of Corrupt Activities Act of 2004 as a person prohibited from doing business
with the public sector
e) The tenderer has not:
i) Abused the Employer’s Supply Chain Management System; or
ii) Failed to perform on any previous contract and has been given a written notice to this effect
f) Has completed the declaration of Interest Form and there are no conflicts of interest which may impact
on the tenderer’s ability to perform the contract in the best interest of the employer or potentially
compromise the tender process.
1.4 CIDB standard conditions of tender
Annex F
(normative)
Standard Conditions of Tender
F.1 General
F.1.1 Actions
F.1.1.1 The employer and each tenderer submitting a tender offer shall comply with these conditions
of tender. In their dealings with each other, they shall discharge their duties and obligations as set out
in F.2 and F.3, timeously and with integrity, and behave equitably, honestly and transparently, comply
with all legal obligations and not engage in anticompetitive practices.
F.1.1.2 The employer and the tenderer and all their agents and employees involved in the tender
process shall avoid conflicts of interest and where a conflict of interest is perceived or known, declare
any such conflict of interest, indicating the nature of such conflict. Tenderers shall declare any potential
conflict of interest in their tender submissions. Employees, agents and advisors of the employer shall
of 78
declare any conflict of interest to whoever is responsible for overseeing the procurement process at
the start of any deliberations relating to the procurement process or as soon as they become aware of
such conflict, and abstain from any decisions where such conflict exists or recuse themselves from the
procurement process, as appropriate.
Note: 1) A conflict of interest may arise due to a conflict of roles which might provide an incentive for
improper acts in some circumstances. A conflict of interest can create an appearance of
impropriety that can undermine confidence in the ability of that person to act properly in his or
her position even if no improper acts result.
indirect or family interests in the tender or outcome of the procurement process and any
personal bias, inclination, obligation, allegiance or loyalty which would in any way affect any
decisions taken.
F.1.1.3 The employer shall not seek and a tenderer shall not submit a tender without having a firm
intention and the capacity to proceed with the contract.
F.1.2 Tender Documents
The documents issued by the employer for the purpose of a tender offer are listed in the tender data.
F.1.3 Interpretation
F.1.3.1 The tender data and additional requirements contained in the tender schedules that are
included in the returnable documents are deemed to be part of these conditions of tender.
F.1.3.2 These conditions of tender, the tender data and tender schedules which are only required for
tender evaluation purposes, shall not form part of any contract arising from the invitation to tender.
F.1.3.3 For the purposes of these conditions of tender, the following definitions apply:
a) conflict of interest means any situation in which:
i) someone in a position of trust has competing professional or personal interests which make
it difficult to fulfill his or her duties impartially;
ii) an individual or organisation is in a position to exploit a professional or official capacity in
some way for their personal or corporate benefit; or
iii) incompatibility or contradictory interests exist between an employee and the organisation
which employs that employee.
b) comparative offer means the price after the factors of a non-firm price and all unconditional
discounts it can be utilised to have been taken into consideration;
c) corrupt practice means the offering, giving, receiving or soliciting of anything of value to
influence the action of the employer or his staff or agents in the tender process;
d) fraudulent practice means the misrepresentation of the facts in order to influence the tender
process or the award of a contract arising from a tender offer to the detriment of the employer,
including collusive practices intended to establish prices at artificial levels;
e) organization means a company, firm, enterprise, association or other legal entity, whether
incorporated or not, or a public body;
f) functionality means the totality of features and characteristics of a product or service that
bear on its ability to satisfy stated or implied needs.
F.1.4 Communication and employer’s agent
Each communication between the employer and a tenderer shall be to or from the employer's agent
only, and in a form that can be readily read, copied and recorded. Communications shall be in the
English language. The employer shall not take any responsibility for non-receipt of communications
of 78
from or by a tenderer. The name and contact details of the employer’s agent are stated in the tender
data.
F.1.5 Cancellation and Re-Invitation of Tenders
F1.5.1 An organ of state may, prior to the award of the tender, cancel a tender if-
(a) due to changed circumstances, there is no longer a need for the services, works or goods requested;
or
(b) funds are no longer available to cover the total envisaged expenditure; or
(c) no acceptable tenders are received.
F1.5.2 The decision to cancel a tender must be published in the CIDB website and in the government
Tender Bulletin for the media in which the original tender invitation was advertised.
F.1.6 Procurement procedures
F.1.6.1 General
Unless otherwise stated in the tender data, a contract will, subject to F.3.13, be concluded with the
tenderer who in terms of F.3.11 is the highest ranked or the tenderer scoring the highest number of
tender evaluation points, as relevant, based on the tender submissions that are received at the closing
time for tenders.
F.1.6.2 Competitive negotiation procedure
F.1.6.2.1 Where the tender data require that the competitive negotiation procedure is to be followed,
tenderers shall submit tender offers in response to the proposed contract in the first round of
submissions. Notwithstanding the requirements of F.3.4, the employer shall announce only the names
of the tenderers who make a submission. The requirements of F.3.8 relating to the material deviations
or qualifications which affect the competitive position of tenderers shall not apply.
F.1.6.2.2 All responsive tenderers, or not less than three responsive tenderers that are highest ranked
in terms of the evaluation method and evaluation criteria stated in the tender data, shall be invited in
each round to enter into competitive negotiations, based on the principle of equal treatment and
keeping confidential the proposed solutions and associated information. Notwithstanding the provisions
of F.2.17, the employer may request that tenders be clarified, specified and fine-tuned in order to
improve a tenderer’s competitive position provided that such clarification, specification, fine-tuning or
additional information does not alter any fundamental aspects of the offers or impose substantial new
requirements which restrict or distort competition or have a discriminatory effect.
F.1.6.2.3 At the conclusion of each round of negotiations, tenderers shall be invited by the employer to
make a fresh tender offer, based on the same evaluation criteria, with or without adjusted weightings.
Tenderers shall be advised when they are to submit their best and final offer.
F.1.6.2.4 The contract shall be awarded in accordance with the provisions of F.3.11 and F.3.13 after
tenderers have been requested to submit their best and final offer.
F.1.6.3 Proposal procedure using the two stage-system
F.1.6.3.1 Option 1
Tenderers shall in the first stage submit technical proposals and, if required, cost parameters around
which a contract may be negotiated. The employer shall evaluate each responsive submission in terms
of the method of evaluation stated in the tender data, and in the second stage negotiate a contract with
the tenderer scoring the highest number of evaluation points and award the contract in terms of these
conditions of tender.
F.1.6.3.2 Option 2
of 78
F.1.6.3.2.1 Tenderers shall submit in the first stage only technical proposals. The employer shall invite
all responsive tenderers to submit tender offers in the second stage, following the issuing of
procurement documents.
F.1.6.3.2.2 The employer shall evaluate tenders received during the second stage in terms of the
method of evaluation stated in the tender data, and award the contract in terms of these conditions of
tender.
F.2 Tenderer’s obligations
F.2.1 Eligibility
F.2.1.1 Submit a tender offer only if the tenderer satisfies the criteria stated in the tender data and the
tenderer, or any of his principals, is not under any restriction to do business with employer
.
F.2.1.2 Notify the employer of any proposed material change in the capabilities or formation of the
tendering entity (or both) or any other criteria which formed part of the qualifying requirements used by
the employer as the basis in a prior process to invite the tenderer to submit a tender offer and obtain
the employer’s written approval to do so prior to the closing time for tenders.
F.2.2 Cost of tendering
F2.2.1 Accept that, unless otherwise stated in the tender data, the employer will not compensate the
tenderer for any costs incurred in the preparation and submission of a tender offer, including the costs
of any testing necessary to demonstrate that aspects of the offer complies with requirements.
F2.2.2 The cost of the tender documents charged by the employer shall be limited to the actual cost
incurred by the employer for printing the documents. Employers must attempt to make available the
tender documents on its website so as not to incur any costs pertaining to the printing of the tender
documents.
F.2.3 Check documents
Check the tender documents on receipt for completeness and notify the employer of any discrepancy
or omission.
F.2.4 Confidentiality and copyright of documents
Treat as confidential all matters arising in connection with the tender. Use and copy the documents
issued by the employer only for the purpose of preparing and submitting a tender offer in response to
the invitation.
F.2.5 Reference documents
Obtain, as necessary for submitting a tender offer, copies of the latest versions of standards,
specifications, conditions of contract and other publications, which are not attached but which are
incorporated into the tender documents by reference.
F.2.6 Acknowledge addenda
Acknowledge receipt of addenda to the tender documents, which the employer may issue, and if
necessary apply for an extension to the closing time stated in the tender data, in order to take the
addenda into account.
F.2.7 Clarification meeting
of 78
Attend, where required, a clarification meeting at which tenderers may familiarize themselves with
aspects of the proposed work, services or supply and raise questions. Details of the meeting(s) are
stated in the tender data.
F.2.8 Seek clarification
Request clarification of the tender documents, if necessary, by notifying the employer at least two
weeks before the closing time stated in the tender data.
F.2.9 Insurance
Be aware that the extent of insurance to be provided by the employer (if any) might not be for the full
cover required in terms of the conditions of contract identified in the contract data. The tenderer is
advised to seek qualified advice regarding insurance.
F.2.10 Pricing the tender offer
F.2.10.1 Include in the rates, prices, and the tendered total of the prices (if any) all duties, taxes (except
Value Added Tax (VAT), and other levies payable by the successful tenderer, such duties, taxes and
levies being those applicable 14 days before the closing time stated in the tender data.
F2.10.2 Show VAT payable by the employer separately as an addition to the tendered total
of the prices.
F.2.10.3 Provide prices that are fixed for the duration of the contract.
F.2.10.4 State the rates and prices in Rand unless instructed otherwise in the tender data. The
conditions of contract identified in the contract data may provide for part payment in other currencies.
F.2.11 Alterations to documents
Do not make any alterations or additions to the tender documents, except to comply with instructions
issued by the employer, or necessary to correct errors made by the tenderer. All signatories to the
tender offer shall initial all such alterations.
F.2.12 Alternative tender offers
F.2.12.1 Unless otherwise stated in the tender data, submit alternative tender offers only if a main
tender offer, strictly in accordance with all the requirements of the tender documents, is also submitted
as well as a schedule that compares the requirements of the tender documents with the alternative
requirements that are proposed.
F.2.12.2 Accept that an alternative tender offer may be based only on the criteria stated in the tender
data or criteria otherwise acceptable to the employer.
F.2.12.3 An alternative tender offer may only be considered in the event that the main tender offer is
the winning tender.
F.2.13 Submitting a tender offer
F.2.13.1 Submit one tender offer only, either as a single tendering entity or as a member in a joint
venture to provide the whole of the works, services or supply identified in the contract data and
described in the scope of works, unless stated otherwise in the tender data.
F.2.13.2 Return all returnable documents to the employer after completing them in their entirety, either
electronically (if they were issued in electronic format) or by writing legibly in non-erasable ink.
of 78
F.2.13.3 Submit the parts of the tender offer communicated on paper as an original plus the number of
copies stated in the tender data, with an English translation of any documentation in a language other
than English, and the parts communicated electronically in the same format as they were issued by the
employer.
F.2.13.4 Sign the original and all copies of the tender offer where required in terms of the tender data.
The employer will hold all authorized signatories liable on behalf of the tenderer. Signatories for
tenderers proposing to contract as joint ventures shall state which of the signatories is the lead partner
whom the employer shall hold liable for the purpose of the tender offer.
F.2.13.5 Seal the original and each copy of the tender offer as separate packages marking the
packages as "ORIGINAL" and "COPY". Each package shall state on the outside the employer's
address and identification details stated in the tender data, as well as the tenderer's name and contact
address.
F.2.13.6 Where a two-envelope system is required in terms of the tender data, place and seal the
returnable documents listed in the tender data in an envelope marked ―financial proposal‖ and place
the remaining returnable documents in an envelope marked ―technical proposal‖. Each envelope shall
state on the outside the employer’s address and identification details stated in the tender data, as well
as the tenderer's name and contact address.
F.2.13.7 Seal the original tender offer and copy packages together in an outer package that states on
the outside only the employer's address and identification details as stated in the tender data.
F.2.13.8 Accept that the employer will not assume any responsibility for the misplacement or premature
opening of the tender offer if the outer package is not sealed and marked as stated.
F.2.13.9 Accept that tender offers submitted by facsimile or e-mail will be rejected by the employer,
unless stated otherwise in the tender data.
F.2.14 Information and data to be completed in all respects
Accept that tender offers, which do not provide all the data or information requested completely and in
the form required, may be regarded by the employer as non-responsive.
F.2.15 Closing time
F.2.15.1 Ensure that the employer receives the tender offer at the address specified in the tender data
not later than the closing time stated in the tender data. Accept that proof of posting shall not be
accepted as proof of delivery.
F.2.15.2 Accept that, if the employer extends the closing time stated in the tender data for any reason,
the requirements of these conditions of tender apply equally to the extended deadline.
F.2.16 Tender offer validity
F.2.16.1 Hold the tender offer(s) valid for acceptance by the employer at any time during the validity
period stated in the tender data after the closing time stated in the tender data.
F.2.16.2 If requested by the employer, consider extending the validity period stated in the tender data
for an agreed additional period with or without any conditions attached to such extension.
F.2.16.3 Accept that a tender submission that has been submitted to the employer may only be
withdrawn or substituted by giving the employer’s agent written notice before the closing time for
tenders that a tender is to be withdrawn or substituted.
of 78
F.2.16.4 Where a tender submission is to be substituted, submit a substitute tender in accordance with
the requirements of F.2.13 with the packages clearly marked as ―SUBSTITUTE.
F.2.17 Clarification of tender offer after submission
Provide clarification of a tender offer in response to a request to do so from the employer during the
evaluation of tender offers. This may include providing a breakdown of rates or prices and correction
of arithmetical errors by the adjustment of certain rates or item prices (or both). No change in the
competitive position of tenderers or substance of the tender offer is sought, offered, or permitted.
Note: Sub-clause F.2.17 does not preclude the negotiation of the final terms of the contract with a preferred tenderer following a
competitive selection process, should the Employer elect to do so.
F.2.18 Provide other material
F.2.18.1 Provide, on request by the employer, any other material that has a bearing on the tender offer,
the tenderer’s commercial position (including notarized joint venture agreements), preferencing
arrangements, or samples of materials, considered necessary by the employer for the purpose of a full
and fair risk assessment. Should the tenderer not provide the material, or a satisfactory reason as to
why it cannot be provided, by the time for submission stated in the employer’s request, the employer
may regard the tender offer as non-responsive.
F.2.18.2 Dispose of samples of materials provided for evaluation by the employer, where required.
F.2.19 Inspections, tests and analysis
Provide access during working hours to premises for inspections, tests and analysis as provided for in
the tender data.
F.2.20 Submit securities, bonds and policies
If requested, submit for the employer’s acceptance before formation of the contract, all securities,
bonds, guarantees, policies and certificates of insurance required in terms of the conditions of contract
identified in the contract data.
F.2.21 Check final draft
Check the final draft of the contract provided by the employer within the time available for the employer
to issue the contract.
F.2.22 Return of other tender documents
If so instructed by the employer, return all retained tender documents within 28 days after the expiry of
the validity period stated in the tender data.
F.2.23 Certificates
Include in the tender submission or provide the employer with any certificates as stated in the tender
data.
F.3 The employer’s undertakings
F.3.1 Respond to requests from the tenderer
of 78
F.3.1.1 Unless otherwise stated in the tender Data, respond to a request for clarification received up to
five working days before the tender closing time stated in the Tender Data and notify all tenderers who
drew procurement documents.
F.3.1.2 Consider any request to make a material change in the capabilities or formation of the tendering
entity (or both) or any other criteria which formed part of the qualifying requirements used to prequalify
a tenderer to submit a tender offer in terms of a previous procurement process and deny any such
request if as a consequence:
a) an individual firm, or a joint venture as a whole, or any individual member of the joint venture fails to
meet any of the collective or individual qualifying requirements;
b) the new partners to a joint venture were not prequalified in the first instance, either as individual firms
or as another joint venture; or
c) in the opinion of the Employer, acceptance of the material change would compromise the outcome
of the prequalification process.
F.3.2 Issue Addenda
If necessary, issue addenda that may amend or amplify the tender documents to each tenderer during
the period from the date that tender documents are available until three days before the tender closing
time stated in the Tender Data. If, as a result a tenderer applies for an extension to the closing time
stated in the Tender Data, the Employer may grant such extension and, shall then notify all tenderers
who drew documents.
F.3.3 Return late tender offers
Return tender offers received after the closing time stated in the Tender Data, unopened, (unless it is
necessary to open a tender submission to obtain a forwarding address), to the tenderer concerned.
F.3.4 Opening of tender submissions
F.3.4.1 Unless the two-envelope system is to be followed, open valid tender submissions in the
presence of tenderers’ agents who choose to attend at the time and place stated in the tender data.
Tender submissions for which acceptable reasons for withdrawal have been submitted will not be
opened
.
F.3.4.2 Announce at the meeting held immediately after the opening of tender submissions, at a venue
indicated in the tender data, the name of each tenderer whose tender offer is opened and, where
applicable, the total of his prices, number of points claimed for its B-BBEE status level and time for
completion for the main tender offer only.
F.3.4.3 Make available the record outlined in F.3.4.2 to all interested persons upon request.
F.3.5 Two-envelope system
F.3.5.1 Where stated in the tender data that a two-envelope system is to be followed, open only the
technical proposal of valid tenders in the presence of tenderers’ agents who choose to attend at the
time and place stated in the tender data and announce the name of each tenderer whose technical
proposal is opened.
F.3.5.2 Evaluate functionality of the technical proposals offered by tenderers, then advise tenderers
who remain in contention for the award of the contract of the time and place when the financial
proposals will be opened. Open only the financial proposals of tenderers, who score in the functionality
evaluation more than the minimum number of points for functionality, stated in the tender data, and
announce the score obtained for the technical proposals and the total price and any points claimed on
B-BBEE status level. Return unopened financial proposals to tenderers whose technical proposals
failed to achieve the minimum number of points for functionality.
of 78
F.3.6 Non-disclosure
Not disclose to tenderers, or to any other person not officially concerned with such processes,
information relating to the evaluation and comparison of tender offers, the final evaluation price and
recommendations for the award of a contract, until after the award of the contract to the successful
tenderer.
F.3.7 Grounds for rejection and disqualification
Determine whether there has been any effort by a tenderer to influence the processing of tender offers
and instantly disqualify a tenderer (and his tender offer) if it is established that he engaged in corrupt
or fraudulent practices.
F.3.8 Test for responsiveness
F.3.8.1 Determine, after opening and before detailed evaluation, whether each tender offer properly
received:
a) complies with the requirements of these Conditions of Tender,
b) has been properly and fully completed and signed, and
c) is responsive to the other requirements of the tender documents.
F.3.8.2 A responsive tender is one that conforms to all the terms, conditions, and specifications of the
tender documents without material deviation or qualification. A material deviation or qualification is one
which, in the Employer's opinion, would:
a) detrimentally affect the scope, quality, or performance of the works, services or supply identified
in the Scope of Work,
b) significantly change the Employer's or the tenderer's risks and responsibilities under the contract, or
c) affect the competitive position of other tenderers presenting responsive tenders, if it were to be
rectified. Reject a non-responsive tender offer and not allow it to be subsequently made responsive by
correction or withdrawal of the non-conforming deviation or reservation.
F.3.9 Arithmetical errors, omissions and discrepancies
F.3.9.1 Check the highest ranked tender or tenderer with the highest number of tender evaluation points
after the evaluation of tender offers in accordance with F.3.11 for:
a) the gross misplacement of the decimal point in any unit rate;
b) omissions made in completing the pricing schedule or bills of quantities; or
c) arithmetic errors in:
i) line item totals resulting from the product of a unit rate and a quantity in bills of quantities or
schedules of prices; or
ii) the summation of the prices.
F3.9.2 The employer must correct the arithmetical errors in the following manner:
a) Where there is a discrepancy between the amounts in words and amounts in figures, the amount
in words shall govern.
b) If bills of quantities or pricing schedules apply and there is an error in the line item total resulting
from the product of the unit rate and the quantity, the line item total shall govern and the rate shall
be corrected. Where there is an obviously gross misplacement of the decimal point in the unit rate,
the line item total as quoted shall govern, and the unit rate shall be corrected.
c) Where there is an error in the total of the prices either as a result of other corrections required by
this checking process or in the tenderer's addition of prices, the total of the prices shall govern and
the tenderer will be asked to revise selected item prices (and their rates if bills of quantities apply)
to achieve the tendered total of the prices.
Consider the rejection of a tender offer if the tenderer does not correct or accept the correction of the
arithmetical error in the manner described above.
of 78
F.3.10 Clarification of a tender offer
Obtain clarification from a tenderer on any matter that could give rise to ambiguity in a contract arising
from the tender offer.
F.3.11 Evaluation of tender offers
F.3.11.1 General
Appoint an evaluation panel of not less than three persons. Reduce each responsive tender offer to a comparative
offer and evaluate it using the tender evaluation method that is indicated in the Tender Data described below:
Method 1: 1. Rank tender offers from the most favourable to the least favourable comparative
Financial offer offer.
there are compelling and justifiable reasons not to do so.
Method 2: 1.Score tender evaluation points for financial offer
Financial offer and 2. Confirm that tenderers are eligible for the preferences claimed and if so, score
Preferences Tender evaluation points for preferencing
lowest.
The award of the contract, unless there are compelling and justifiable reasons not
to do so.
Method 3: 1.Score quality, rejecting all tender offers that fail to score the minimum number
Financial offer and of points for Quality stated in the Tender data
Quality 2. Score tender evaluation points for financial offer
the award of the contract, unless there are compelling and justifiable reasons not
to do so.
Method 4: 1.Score quality, rejecting all tender offers that fail to score the minimum number
Financial offer, quality of points for Quality stated in the Tender data.
And preferences 2. Score tender evaluation points for financial offer.
Preferences 3. Confirm that tenderers are eligible for the preferences claimed, and if so, score
tender evaluation points for preferencing.
lowest.
the award of the contract, unless there are compelling and justifiable reasons not
to do so.
Where:
Pm = the comparative offer of the most favourable tender offer.
P = the comparative offer of tender offer under consideration.
F.3.11.3 Scoring quality (functionality)
Score quality in each of the categories in accordance with the Tender Data and calculate total score
for quality.
F.3.12 Insurance provided by the employer
of 78
If requested by the proposed successful tenderer, submit for the tenderer's information the policies and /
or certificates of insurance which the conditions of contract identified in the contract data, require the
employer to provide.
F.3.13 Acceptance of tender offer
Accept the tender offer, if in the opinion of the employer, it does not present any risk and only if the
tenderer:
a) is not under restrictions, or has principals who are under restrictions, preventing participating in
the employer’s procurement,
b) can, as necessary and in relation to the proposed contract, demonstrate that he or she possesses
the professional and technical qualifications, professional and technical competence, financial
resources, equipment and other physical facilities, managerial capability, reliability, experience
and reputation, expertise and the personnel, to perform the contract,
c) has the legal capacity to enter into the contract,
d) is not insolvent, in receivership, under Business Rescue as provided for in chapter 6 of the
Companies Act, 2008, bankrupt or being wound up, has his affairs administered by a court or a
judicial officer, has suspended his business activities, or is subject to legal proceedings in respect
of any of the foregoing,
e) complies with the legal requirements, if any, stated in the tender data, and
f) is able, in the opinion of the employer, to perform the contract free of conflicts of interest.
F.3.14 Prepare contract documents
F.3.14.1 If necessary, revise documents that shall form part of the contract and that were issued by the
employer as part of the tender documents to take account of:
a) addenda issued during the tender period,
b) inclusion of some of the returnable documents, and
c) other revisions agreed between the employer and the successful tenderer.
F.3.14.2 Complete the schedule of deviations attached to the form of offer and acceptance, if any.
F.3.15 Complete adjudicator's contract
Unless alternative arrangements have been agreed or otherwise provided for in the contract, arrange for
both parties to complete formalities for appointing the selected adjudicator at the same time as the main
contract is signed.
F.3.16 Notice to unsuccessful tenderers
F.3.16.1 Notify the successful tenderer of the employer's acceptance of his tender offer by completing
and returning one copy of the form of offer and acceptance before the expiry of the validity period stated
in the tender data, or agreed additional period.
F.3.16.2 After the successful tenderer has been notified of the employer’s acceptance of the tender, notify
other tenderers that their tender offers have not been accepted.
F.3.17 Provide copies of the contracts
Provide to the successful tenderer the number of copies stated in the Tender Data of the signed copy of
the contract as soon as possible after completion and signing of the form of offer and acceptance.
F.3.18 Provide written reasons for actions taken
of 78
Provide upon request written reasons to tenderers for any action that is taken in applying these conditions
of tender, but withhold information which is not in the public interest to be divulged, which is considered
to prejudice the legitimate commercial interests of tenderers or might prejudice fair competition between
tenderers.
F3.19 Transparency in the procurement process
F3.19.1 The CIDB prescripts require that tenders must be advertised and be registered on the CIDB i-Tender
system.
F3.19.2 The employer must adopt a transparency model that incorporates the disclosure and
accountability as transparency requirements in the procurement process.
F3.19.3 The transparency model must identify the criteria for selection of projects, project information
template and the threshold value of the projects to be disclosed in the public domain at various intervals
of delivery of infrastructure projects.
F3.19.4 The client must publish the information on a quarterly basis which contains the following
information:
▪ Procurement planning process
▪ Procurement method and evaluation process
▪ Contract type
▪ Contract status
▪ Number of firms tendering
▪ Cost estimate
▪ Contract title
▪ Contract firm(s)
▪ Contract price
▪ Contract scope of work
▪ Contract start date and duration
▪ Contract evaluation reports
F3.19.5 The employer must establish a Consultative Forum which will conduct a random audit in the
implementation of the transparency requirements in the procurement process.
F3.19.6 Consultative Forum must be an independent structure from the bid committees.
F3.19.7 The information must be published on the employer’s website.
F 3.19.8 Records of such disclosed information must be retained for audit purposes.
of 78
Mbd 3.1
Pricing schedule – firm prices
(Purchases)
Note: price adjustments will be allowed at the periods and times specified in the
Bidding documents (including prices subject to rates of exchange
Variations)
In cases where different delivery points influence the pricing, a
Separate
Pricing schedule must be submitted for each delivery point
Name of Bidder............................................................Bid Number.............................................................
Closing Time ...........................................................Closing Date .........................................................
Offer to be valid for 120 days from the closing date of bid.
_
Item quantity description bid price in RSA currency
NO. ** (all applicable taxes included)
1 1 Cost per unit R
Note:
Required by: ........................................
At: ........................................
Brand and Model ........................................
Country of Origin ........................................
Does the offer comply with the specification(s)? *YES/NO
If not to specification, indicate deviation(s) ........................................
Period required for delivery ........................................
Delivery basis ...........................................
Note: All delivery costs must be included in the bid price, for delivery at the prescribed destination.
** “all applicable taxes” includes value- added tax, pay as you earn, income tax, unemployment insurance fund
contributions and skills development levies.
of 78
Mbd 3.2
Pricing schedule – non-firm prices
(Purchases)
Note: price adjustments will be allowed at the periods and times specified in the
Bidding documents.
In cases where different delivery points influence the pricing, a separate pricing
Schedule must be submitted for each delivery point
Name of Bidder............................................. Bid number...................................................
Closing Time ................................................ Closing Date ................................................
Offer to be valid for 120 days from the closing date of bid.
Item quantity description bid price in RSA currency
NO. (all applicable taxes incuded)
1 Cost per unit R
Note:
Required by: ........................................
At: ........................................
Brand and Model ........................................
Country of Origin ........................................
Does the offer comply with the specification(s)? *YES/NO
If not to specification, indicate deviation(s) ........................................
Period required for delivery ........................................
Delivery basis ...........................................
Note: All delivery costs must be included in the bid price, for delivery at the prescribed destination.
** “all applicable taxes” excludes value- added tax, pay as you earn, income tax, unemployment insurance fund contributions
and skills development levies.
of 78
Mbd 3.2
Price adjustments
A non-firm prices subject to escalation
The assessed contract price adjustments implicit in non firm prices when
Calculating the comparative prices
Following formula:
R1t R 2t R 3t R 4t Pa = (1 − V )Pt D1 + D 2 + D3 + D 4 + VPt
R1o R 2o R 3o R 4o
Where:
Pa = The new escalated price to be calculated.
(1-V) Pt = 85% of the original bid price. Note that Pt must always be the original bid price
and not an escalated price.
D1, D2.. = Each factor of the bid price eg. labour, transport, clothing, footwear, etc. The total
of the various factors D1,D2...etc. must add up to 100%.
R1t, R2t...... = Index figure obtained from new index (depends on the number of factors used).
R1o, R2o = Index figure at time of bidding.
VPt = 15% of the original bid price. This portion of the bid price remains firm i.e. it is not
subject to any price escalations.
Index.......... Dated.......... Index.......... Dated.......... Index.......... Dated..........
Index.......... Dated.......... Index.......... Dated.......... Index.......... Dated..........
Of the various factors must add up to 100%.
Factor
Percentage of bid price
(D1, D2 etc. eg. Labour, transport etc.)
of 78
Mbd 3.2
B prices subject to rate of exchange variations
the items to South African currency, which portion of the price is subject to rate of exchange variations and the
amounts remitted abroad.
Amount in
Portion of
Foreign
Particulars of financial price
Item NO price currency rate currency
Institution subject to
Remitted
Roe
Abroad
ZAR=
ZAR=
ZAR=
ZAR=
ZAR=
ZAR=
monthly exchange rates as issued by your commercial bank for the periods indicated hereunder: (Proof from bank
required)
Date date from which date until which
Average monthly exchange rates for documentation new calculated new calculated
The period: must be submitted prices will become price will be
To this office effective effective
of 78
Part 3: agreements and contract data
3.1 Form of offer
The Chief Executive Officer
CITY POWER Johannesburg
Reuven, JOHANNESBURG
SIR, I (or We), the undersigned hereby BID and should this BID be accepted, undertake to supply and deliver
the GOODS AND SERVICES as described and referred to in the Specification, Schedule of Quantities,
Drawings and Schedule of Prices Conditions of Contract, and have no objection to enter into the formal
Contract with the said City Power, embodying the said Conditions of Contract, Specifications, Schedule of
Quantities, Drawings and Schedule of Prices, in consideration of the sum (Inclusive of Value Added Tax)
section of the scope as indicated under the headings below.
.
Amount in Figures
(VAT Incl.)
Amount in Words
based on the provisional quantities specified and unit rates incorporated by me (or us) in the said Schedule of
Quantities and Schedule of Prices or such other sum as may be ascertained in accordance with the
aforementioned documents.
Name of Authorised Person Signature of Authorised Person Date
If the Bidder is a Company, Corporation or Firm, state by what authority the person signing does so, whether
by Articles of Association, Resolution, Power of Attorney, or otherwise.
I (We) ___________________________________ am (are) authorised to enter into this contract on behalf of
______________________________ by virtue of ____________________
dated the ______ day of ________________ 20____, a certified copy of which is attached to this BID.
Witnesses: ____________________________ ____________________________
Signature Date
of 78
Mbd 7.1
Contract form - purchase of goods/works
This form must be filled in duplicate by both the successful bidder (part 1) and the
Purchaser (part 2). Both forms must be signed in the original so that the
Successful bidder and the purchaser would be in possession of originally signed
Contracts for their respective records.
Part 1 (to be filled in by the bidder)
documents to (name of institution).............................................................in accordance with
the requirements and specifications stipulated in bid number............................. at the price/s
quoted. My offer/s remain binding upon me and open for acceptance by the purchaser during the
validity period indicated and calculated from the closing time of bid.
agreement:
(i) Bidding documents, viz
Contribution in terms of the Preferential Procurement Regulations 2011;
(ii) General Conditions of Contract; and
(iii) Other (specify)
rate(s) quoted cover all the goods and/or works specified in the bidding documents; that the price(s)
and rate(s) cover all my obligations and I accept that any mistakes regarding price(s) and rate(s) and
calculations will be at my own risk.
devolving on me under this agreement as the principal liable for the due fulfillment of this contract.
regarding this or any other bid.
Name (print) .................................................
Witnesses capacity .................................................
1 .................................... Signature .................................................
Date .................................................
of 78
Mbd 7.1
Contract form - purchase of goods/works
Part 2 (to be filled in by the purchaser)
your bid under reference number.............................dated....................................for the supply
of goods/works indicated hereunder and/or further specified in the annexure(s).
An official order indicating delivery instructions is forthcoming.
I undertake to make payment for the goods/works delivered in accordance with the terms and
conditions of the contract, within 30 (thirty) days after receipt of an invoice accompanied by the delivery
note.
Technical Specifications
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)Cyber security enhancement
Pricing Schedule
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)Part 1: tendering procedure
1.1 Invitation to bid ( mbd 1 )
1.2 Tender data
1.3 CIDB standard condition of tender
Part 2: pricing data
2.1 Pricing instruction
2.2 Firm prices form (mbd 3.1)
2.3 Non-firm prices form (mbd 3.2)
2.4 Price schedule
Part 3: agreements and contract data
3.1 Form of acceptance
3.2 Contract data
3.3 Formal contract (mbd 7.1)
Part 4: returnable documents
4.1 Returnable documents required for evaluation purpose
in arrears for more than 90 days & not older than 3 months or Lease agreement must be duly signed
by both the lessor or lessee
consolidated certificate or sworn statement in case of Joint Venture (Failure to attach certificate
will lead to non- allocation of points). Refer to evaluation criteria for more information regarding
specific goals.
4.2 Other documents required for evaluation purpose
4.3 Documents that will be incorporated in the contract
Part 5: scope of work
5.1 Evaluation criteria
5.2 Pricing schedule (bill of quantities)
5.3 Specifications
of 78
1.1 Tender notice and invitation to tender
Invitation to bid mbd1
Mbd 1
for Uniformity published in August 2019 are included in this document.
F1.1 The employer is City Power Johannesburg (SOC) Ltd
F1.2 The tender documents issued by the employer comprise:
Part 1: Tendering procedure
1.1 Invitation to Bid ( MBD 1 )
1.2 Tender data
1.3 CIDB Standard conditions of tender (updated August 2019)
Part 2: Pricing data
2.1 Pricing instruction
2.2 Firm Prices Form (MBD 3.1)
2.3 Non-firm prices form (MBD 3.2)
2.4 Price Schedule
Part 3: Agreements and contract data
3.1 Form of acceptance
3.2 Contract data
3.3 Formal contract (MBD 7.1)
Part 4: Returnable documents
.1 Returnable documents required for evaluation purpose
not be in arrears for more than 90 days & not older than 3 months or Lease agreement must
be duly signed by both the lessor or lessee
A consolidated certificate or sworn statement in case of Joint Venture (Failure to attach
certificate will lead to non- allocation of points). Refer to evaluation criteria for more
information regarding specific goals.
of 78
4.2 Other documents required for evaluation purpose
4.3 Documents that will be incorporated in the contract
Part 5: Scope of work
5.1 Evaluation Criteria
5.2 Pricing Schedule (Bill of Quantities)
5.3 Specifications
F1.4 The employer’s agent is:
Name: Zandile Mshweshwe
Address: 40 Heronmere Road, Booysens, Johannesburg
Tel: 011 490 7838
E-mail: [email protected]
F1.5 The employer’s right to accept or reject any tender offer.
F1.5.1 The employer may accept or reject any variation, deviation, tender offer, or
alternative tender, and may cancel the tender process and reject all tender offers
at any time before the formation of contract. The employer shall not accept or
incur any liability to a tenderer for such cancellation and rejection but will give
written reasons for such action upon written request to do so.
F2.1 Only those bidders who satisfy the eligibility criteria are eligible to submit
tenders and the tenderer, or his principals, is not under any restriction to do
business with employer.
the documents will result in the bidder not being evaluated further)
quantities in full will result in your submission being regarded as non-
responsive
F2.7 Clarification meeting are: N/A
Location: N/A
Date: N/A
Starting time: N/A
F2.8 Requests for clarification from the employer will be allowed up to five
working days before the bid closes and all questions related to the bid should be
communicated via email to the buyer responsible for the bid.
F2.12 If a tenderer wishes to submit an alternative offer, the only criteria
permitted for such alternative offer is that it demonstrably satisfies the Employer’s
standards and requirements, the details of which may be obtained from the
Employer’s agent.
of 78
b) The tenderer is registered with Central System Database (CSD)
c) The tenderer is not in arrears for more than 3 months with municipal rates and taxes and municipal
service charges
d) The tenderer or any of its directors is not listed on the Register of Tender Defaulters in terms of the
Prevention and Combating of Corrupt Activities Act of 2004 as a person prohibited from doing business
with the public sector
e) The tenderer has not:
i) Abused the Employer’s Supply Chain Management System; or
ii) Failed to perform on any previous contract and has been given a written notice to this effect
f) Has completed the declaration of Interest Form and there are no conflicts of interest which may impact
on the tenderer’s ability to perform the contract in the best interest of the employer or potentially
compromise the tender process.
1.4 CIDB standard conditions of tender
weeks before the closing time stated in the tender data.
F.2.9 Insurance
Be aware that the extent of insurance to be provided by the employer (if any) might not be for the full
cover required in terms of the conditions of contract identified in the contract data. The tenderer is
advised to seek qualified advice regarding insurance.
F.2.10 Pricing the tender offer
F.2.10.1 Include in the rates, prices, and the tendered total of the prices (if any) all duties, taxes (except
Value Added Tax (VAT), and other levies payable by the successful tenderer, such duties, taxes and
levies being those applicable 14 days before the closing time stated in the tender data.
F2.10.2 Show VAT payable by the employer separately as an addition to the tendered total
of the prices.
F.2.10.3 Provide prices that are fixed for the duration of the contract.
F.2.10.4 State the rates and prices in Rand unless instructed otherwise in the tender data. The
conditions of contract identified in the contract data may provide for part payment in other currencies.
F.2.11 Alterations to documents
and instantly disqualify a tenderer (and his tender offer) if it is established that he engaged in corrupt
or fraudulent practices.
F.3.8 Test for responsiveness
F.3.8.1 Determine, after opening and before detailed evaluation, whether each tender offer properly
received:
a) complies with the requirements of these Conditions of Tender,
b) has been properly and fully completed and signed, and
c) is responsive to the other requirements of the tender documents.
F.3.8.2 A responsive tender is one that conforms to all the terms, conditions, and specifications of the
tender documents without material deviation or qualification. A material deviation or qualification is one
which, in the Employer's opinion, would:
a) detrimentally affect the scope, quality, or performance of the works, services or supply identified
in the Scope of Work,
b) significantly change the Employer's or the tenderer's risks and responsibilities under the contract, or
c) affect the competitive position of other tenderers presenting responsive tenders, if it were to be
rectified. Reject a non-responsive tender offer and not allow it to be subsequently made responsive by
correction or withdrawal of the non-conforming deviation or reservation.
F.3.9 Arithmetical errors, omissions and discrepancies
F.3.9.1 Check the highest ranked tender or tenderer with the highest number of tender evaluation points
after the evaluation of tender offers in accordance with F.3.11 for:
a) the gross misplacement of the decimal point in any unit rate;
b) omissions made in completing the pricing schedule or bills of quantities; or
c) arithmetic errors in:
i) line item totals resulting from the product of a unit rate and a quantity in bills of quantities or
schedules of prices; or
ii) the summation of the prices.
F3.9.2 The employer must correct the arithmetical errors in the following manner:
a) Where there is a discrepancy between the amounts in words and amounts in figures, the amount
in words shall govern.
b) If bills of quantities or pricing schedules apply and there is an error in the line item total resulting
from the product of the unit rate and the quantity, the line item total shall govern and the rate shall
be corrected. Where there is an obviously gross misplacement of the decimal point in the unit rate,
the line item total as quoted shall govern, and the unit rate shall be corrected.
c) Where there is an error in the total of the prices either as a result of other corrections required by
this checking process or in the tenderer's addition of prices, the total of the prices shall govern and
the tenderer will be asked to revise selected item prices (and their rates if bills of quantities apply)
to achieve the tendered total of the prices.
of tender, but withhold information which is not in the public interest to be divulged, which is considered
to prejudice the legitimate commercial interests of tenderers or might prejudice fair competition between
tenderers.
F3.19 Transparency in the procurement process
F3.19.1 The CIDB prescripts require that tenders must be advertised and be registered on the CIDB i-Tender
system.
F3.19.2 The employer must adopt a transparency model that incorporates the disclosure and
accountability as transparency requirements in the procurement process.
F3.19.3 The transparency model must identify the criteria for selection of projects, project information
template and the threshold value of the projects to be disclosed in the public domain at various intervals
of delivery of infrastructure projects.
F3.19.4 The client must publish the information on a quarterly basis which contains the following
information:
▪ Procurement planning process
▪ Procurement method and evaluation process
▪ Contract type
▪ Contract status
▪ Number of firms tendering
▪ Cost estimate
▪ Contract title
▪ Contract firm(s)
▪ Contract price
▪ Contract scope of work
▪ Contract start date and duration
▪ Contract evaluation reports
F3.19.5 The employer must establish a Consultative Forum which will conduct a random audit in the
implementation of the transparency requirements in the procurement process.
F3.19.6 Consultative Forum must be an independent structure from the bid committees.
F3.19.7 The information must be published on the employer’s website.
F 3.19.8 Records of such disclosed information must be retained for audit purposes.
of 78
Mbd 3.1
Pricing schedule – firm prices
(Purchases)
Note: price adjustments will be allowed at the periods and times specified in the
Bidding documents (including prices subject to rates of exchange
Variations)
monthly exchange rates as issued by your commercial bank for the periods indicated hereunder: (Proof from bank
required)
based on the provisional quantities specified and unit rates incorporated by me (or us) in the said Schedule of
2016
3.5.3 SUPPLIERS invoice(s) shall be fully detailed in respect of:
3.5.3.1 Information
3.5.3.2 Value Added Tax
rate invoiced.
3.5.3.3 Structure of Invoice
3.6 Statement of accounts
3.6.1 SUPPLIER shall submit an original monthly statement to the Financial Department by not later than
the 10th day of the month following the month in which the GOODS AND SERVICES were delivered.
3.6.2 Said statement must reflect the following:
preceding statement).
Financial Requirements
Source: Bid Document CYBER SECURITY ENHANCEMENT 2651S.pdf (TENDER)Payment Terms: payment terms are 30 days from the date of receipt of the invoice and statement of
account.
3.4 Method of payment
3.4.1 SUPPLIER must elect payment by cheque or electronic fund transfer for the purpose of a contract
within 14 (fourteen) days of a purchase order being awarded. SUPPLIER must exercise its choice in
writing and submit it to CITY POWER’s Financ
Description
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER)Cyber security enhancement
Contact Information
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER){"name":null,"email":"[email protected]","phone":null,"department":null,"address":"er 2026"}
Evaluation Criteria
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER)1St stage of bid evaluation functionality total score: 100%
Threshold (minimum score): 80%
2Nd stage of bid evaluation specific goals
Specific goals b-bbee (specific goals): 20
No Specific goal Requirement Points
consolidated B-BBEE certificate from verification
points owners)
Pricing Schedule
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER)complete the Bill of quantities in full will result in
your submission being regarded as non-responsive.
1St stage of bid evaluation functionality total score: 100%
Threshold (minimum score): 80%
Compliance Requirements
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER)(Please note that no e-mailed or faxed documents will
CIDB GRADING ( if applicable) N/A
MANDATORY REQUIREMENTS Bill of quantities must be completed in full. Failure to
complete the Bill of quantities in full will result in
B-BBEE Details: [email protected]
Submission of bids bids must be submitted at the tender box
Situated at 40 hereonmere road, reuven,
BOOYSENS (Tender Advice Centre)
(Please note that no e-mailed or faxed documents will
be accepted)
CIDB GRADING ( if applicable) N/A
MANDATORY REQUIREMENTS Bill of quantities must be completed in full. Failure to
complete the Bill of quantities in full will result in
your submission being regarded as non-responsive.
1St stage of bid evaluation functionality total score: 100%
Threshold (minimum score): 80%
2Nd stage of bid evaluation specific goals
Specific goals b-bbee (specific goals): 20
No Specific goal Requirement Points
three (3) months) of BEE certificate / sworn affidavit, shareholding
consolidated B-BBEE certificate from verification
agency if bidder is JV/consortium and certified copies
points owners)
Enterprise owned by black youth with at least 51% three (3) months) of BEE certificate / sworn affidavit,
shareholding consolidated B-BBEE certificate from verification
owners)
Geographical area lease agreement and certified copies (not older
than three (3) months of ID copies of owners)
Number of
Section
Source: Bid Advert Template-CYBER SECURITY (002).pdf (TENDER)1St stage of bid evaluation functionality total score: 100%
Threshold (minimum score): 80%
2Nd stage of bid evaluation specific goals
Specific goals b-bbee (specific goals): 20
No Specific goal Requirement Points
consolidated B-BBEE certificate from verification
points owners)
Important Dates
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown){"briefingSession":"{"date":null,"time":null,"venue":"ion procedures.","is_compulsory":false}"}
Contact Information
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown){"name":null,"email":null,"phone":null,"department":null,"address":"Technology"}
Evaluation Criteria
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)expressly listed but necessary for full functionality.
ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection — Information security
ISO/IEC 27002:2022: Information security, cybersecurity and privacy protection — Information security controls
ISO/IEC 27035: Information technology — Information security incident management
Technical Specifications
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)The threat landscape is increasingly dynamic, with advanced cyber threats emerging continuously. To
proactively detect, analyse, and respond to these threats, City Power requires an intelligent network detection
and cyber threat‐hunting capability that leverages advanced analytics, automation, and machine‐learning
techniques. Such a solution is essential for identifying malicious activity, reducing exposure, and strengthening
the overall security posture of the ICT environment.
City Power requires this capability to be delivered as a complete turnkey solution. The appointed Service
Provider shall be responsible for the end-to-end delivery of the solution, including the pre-deployment
assessment, solution design, supply of all hardware, software and licensing, installation, configuration,
integration with the existing ICT and security environment, testing, commissioning, documentation, training,
knowledge transfer, and ongoing support and maintenance for the duration of the contract. City Power shall
take receipt of a fully operational, tested and supported solution and shall not be required to source, integrate
or commission any component of the solution separately.
City Power requires the appointment of a suitably qualified and experienced ICT Security Services Partner to
design, supply, implement, and support an advanced Network Detection and Response (NDR) solution.
The solution shall be procured, delivered and implemented on a turnkey basis. The appointed Service Provider
shall carry single-point accountability for the complete solution, and the price offered shall be all-inclusive of
every item, service and activity necessary to place the solution into full production use, whether or not each
such item is expressly listed in this specification.
The scope of work includes, but is not limited to, the following:
1.1 Solution Acquisition and Implementation
1.1.1 Supply and implementation of an intelligent ICT security solution capable of proactively detecting,
analysing, and responding to cyber threats across the network environment.
1.1.1 Ensure the solution incorporates advanced analytics, artificial intelligence (AI), and machine-learning
capabilities to identify malicious activity, information leakage, and potential attack vectors.
1.2 Threat Detection and Hunting
1.2.1 Implement systems that continuously analyse network events and security logs to detect anomalous
and malicious behaviour.
1.2.2 Provide cyber threat-hunting capabilities that enable proactive identification, investigation,
mitigation, and remediation of security threats.
1.3 Prevention of Cyber Incidents
1.3.1 Ensure the implemented solution effectively prevents malicious attacks, data breaches, and business
disruptions resulting from cyber-attacks.
1.3.2 Strengthen City Power’s overall ICT security posture and resilience against evolving cyber threats.
1.4 Licensing, Support, and Maintenance
1.4.1 Provide all required software licensing for the duration of the contract.
Standard for ICT cyber security reference rev
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
1.4.2 Deliver ongoing technical support, maintenance, updates, and patches to ensure optimal system
performance and security effectiveness.
1.5 Secure Operational Environment
1.5.1 Ensure the solution operates within a secure and compliant environment, aligned with City Power’s
ICT security policies and best-practice standards.
1.6 Pre-Deployment Assessment
1.6.1 Conduct a mandatory pre-deployment assessment of the City Power ICT and operational technology
environment prior to finalising the solution design, sizing, licensing and implementation plan.
1.6.2 Produce and present a Pre-Assessment Report covering the technical readiness of the environment
for deployment, an analysis of the user accounts that actively log on to the environment, an inventory
of the machines and devices connected to the environment, and a history of the attacks experienced
by City Power together with their associated types.
1.7 Turnkey Delivery, Commissioning and Handover
1.7.1 Deliver, install, configure, integrate, test, commission and hand over a fully operational solution as a
single, complete package under one point of accountability.
1.7.2 Provide all hardware, software, licences, subscriptions, connectors, cabling, mounting and ancillary
infrastructure required for the solution to operate at the required capacity, including items not
expressly listed but necessary for full functionality.
1.7.3 Provide as-built documentation, operational run-books and formal acceptance testing prior to
handover.
The following documents contain provisions that, through reference in the text, constitute requirements of this
specification. At the time of publication, the editions indicated were valid. All standards and specifications are
subject to revision, and parties to agreements based on this standard are encouraged to investigate the
possibility of applying the most recent editions of the documents listed below.
COBIT: Control Objectives for Information and Related Technology. It is a framework created by the ISACA
(Information Systems Audit and Control Association) for IT governance and management
KING IV: Technology and Information Governance
TOGAF: The Open Group Architecture Framework is a framework for enterprise architecture that provides an
approach for designing, planning, implementing, and governing an enterprise information technology
architecture.
POPI Act: Protection of Personal Information Act, 2013
GWEA: Government-Wide Enterprise Architecture framework
ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection — Information security
management systems — Requirements
Standard for ICT cyber security reference rev
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
ISO/IEC 27002:2022: Information security, cybersecurity and privacy protection — Information security controls
ISO/IEC 27035: Information technology — Information security incident management
MITRE ATT&CK: Globally accessible knowledge base of adversary tactics and techniques based on real-world
observations, incorporating both the Enterprise and ICS matrices
NIST CSF: National Institute of Standards and Technology Cybersecurity Framework
The definitions and abbreviations in the above document (Normative Reference) shall apply to this specification.
In addition, the following terms and acronyms are used in this document:
Term meaning
ICT Information and Communication Technology
SLA Service Level Agreement
IT Information Technology
DR Disaster Recovery
IPS Intrusion Prevention System
NDR Network Detection and Response
SOC Security Operations Centre
SIEM Security Information and Event Management
NAC Network Admission Control
NGFW Next-Generation Firewall
AES Advanced Encryption Standard
IPsec Internet Protocol Security
CMDB Configuration Management Database
VPN Virtual Private Network
IoT Internet of Things
OT Operational Technology
API Application Programming Interface
ATT&CK Adversarial Tactics, Techniques and Common Knowledge (MITRE framework)
AWS Amazon Web Services
BOM Bill of Materials
C2 Command and Control
DNS Domain Name System
DPI Deep Packet Inspection
eBPF Extended Berkeley Packet Filter
EDR Endpoint Detection and Response
HTTP/S Hypertext Transfer Protocol / Hypertext Transfer Protocol Secure
IOC Indicator of Compromise
LDAP Lightweight Directory Access Protocol
MFA Multi-Factor Authentication
MTTD Mean Time to Detect
MTTR Mean Time to Respond
Standard for ICT cyber security reference rev
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
Term meaning
NetFlow Network flow record protocol used to collect IP traffic information
PCAP Packet Capture
POPIA Protection of Personal Information Act, 2013
RBAC Role-Based Access Control
RDP Remote Desktop Protocol
SaaS Software as a Service
SOAR Security Orchestration, Automation and Response
SPAN Switched Port Analyser (port mirroring)
TAP Test Access Point
TLS Transport Layer Security
UEBA User and Entity Behaviour Analytics
VM Virtual Machine
VPC Virtual Private Cloud
XDR Extended Detection and Response
Methodology
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)specification. At the time of publication, the editions indicated were valid. All standards and specifications are
subject to revision, and parties to agreements based on this standard are encouraged to investigate the
possibility of applying the most recent editions of the documents listed below.
COBIT: Control Objectives for Information and Related Technology. It is a framework created by the ISACA
(Information Systems Audit and Control Association) for IT governance and management
KING IV: Technology and Information Governance
TOGAF: The Open Group Architecture Framework is a framework for enterprise architecture that provides an
approach for designing, planning, implementing, and governing an enterprise information technology
architecture.
POPI Act: Protection of Personal Information Act, 2013
GWEA: Government-Wide Enterprise Architecture framework
ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection — Information security
management systems — Requirements
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
5.1.4 Identify risks, constraints and dependencies that may affect deployment.
5.1.5 Confirm the final bill of materials, licensing quantities and implementation plan.
5.2 Technical Assessment for Solution Deployment
5.2.1 Review of the network architecture and topology, covering the core, distribution and access layers, data
centres, DMZ, remote sites, substations, cloud environments and OT networks.
5.2.2 Identification of all required collection points, including SPAN and mirror ports, TAP locations, packet
broker requirements, cloud mirroring and flow log sources, and server sensor coverage.
5.2.3 Measurement of current traffic volumes and peaks at each collection point, together with the growth
trend, in order to confirm sensor sizing and licensing quantities.
5.2.4 Assessment of the segmentation model and the IT and OT boundary, and identification of blind spots
where traffic is currently not visible.
5.2.5 Assessment of the existing security toolset, including SIEM, SOAR, NGFW, NAC, EDR, email security and
directory services, and the integration effort required for each.
5.2.6 Assessment of available infrastructure, including rack space, power, cooling, compute, storage,
virtualisation and network capacity, and identification of any shortfalls.
5.2.7 Assessment of the cloud environments in use, including subscriptions, VPCs and VNets, workloads, and
the flow log and traffic mirroring capability available in each.
5.2.8 Confirmation of the protocols in use, including operational technology protocols, and confirmation that
the proposed solution decodes each of them.
5.2.9 Identification of constraints, change control requirements, outage windows and operational risks
associated with deployment.
5.2.10 A proposed deployment architecture, phased implementation plan and cut-over approach.
5.3 User and Access Analysis
Quality Management
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)A quality management system/plan shall be set up to assure quality during manufacture, installation, removal,
transportation, and disposal. Guidance on the requirements for a quality management system may be found in
the following standards: ISO 9001:2015. The details shall be subject to an agreement between the purchaser
and the supplier.
assessment, solution design, supply of all hardware, software and licensing, installation, configuration,
integration with the existing ICT and security environment, testing, commissioning, documentation, training,
knowledge transfer, and ongoing support and maintenance for the duration of the contract. City Power shall
take receipt of a fully operational, tested and supported solution and shall not be required to source, integrate
or commission any component of the solution separately.
1.6 Pre-Deployment Assessment
1.6.1 Conduct a mandatory pre-deployment assessment of the City Power ICT and operational technology
environment prior to finalising the solution design, sizing, licensing and implementation plan.
1.6.2 Produce and present a Pre-Assessment Report covering the technical readiness of the environment
for deployment, an analysis of the user accounts that actively log on to the environment, an inventory
of the machines and devices connected to the environment, and a history of the attacks experienced
by City Power together with their associated types.
1.7 Turnkey Delivery, Commissioning and Handover
1.7.1 Deliver, install, configure, integrate, test, commission and hand over a fully operational solution as a
single, complete package under one point of accountability.
1.7.2 Provide all hardware, software, licences, subscriptions, connectors, cabling, mounting and ancillary
infrastructure required for the solution to operate at the required capacity, including items not
expressly listed but necessary for full functionality.
1.7.3 Provide as-built documentation, operational run-books and formal acceptance testing prior to
handover.
requirement may render a bid non-responsive.
4.2.1 Turnkey Solution Delivery
4.2.1.1 The solution shall be delivered as a complete turnkey solution, with the Service Provider
accountable for design, supply, delivery, installation, configuration, integration, testing,
commissioning, documentation, training, handover and support.
4.2.1.2 The Service Provider shall supply all hardware, software, licences, subscriptions, connectors and
ancillary components required for the solution to operate at the required capacity.
4.2.1.3 The Service Provider shall provide all professional services required to place the solution into full
production use, including project management, design workshops, migration and cut-over.
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
4.2.1.4 Any item not expressly listed in this specification but reasonably necessary for the correct and
complete functioning of the solution shall be deemed to be included in the Service Provider's offer.
4.2.1.5 The Service Provider shall provide a documented implementation plan with milestones,
deliverables, dependencies, resource allocations and acceptance criteria.
4.2.1.6 Formal acceptance testing shall be conducted against agreed criteria and signed off by City Power
before the solution is regarded as commissioned.
4.2.2 Network Visibility and Monitoring
4.2.2.1 The solution shall continuously monitor and analyse both north-south and east-west traffic across
the corporate, data centre, cloud and operational technology environments.
4.2.2.2 The solution shall provide continuous, passive monitoring that does not degrade network
performance, latency or availability.
4.2.2.3 The solution shall automatically discover, classify and profile all devices communicating on the
monitored networks, including unmanaged, IoT and OT devices.
4.2.2.4 The solution shall maintain an up-to-date inventory of monitored assets, exportable and
reconcilable against the City Power CMDB and asset register.
4.2.2.5 The solution shall present real-time and historical views of network communications, including peer
relationships, protocols, volumes, directions and session detail.
4.2.2.6 The solution shall identify and report on blind spots where traffic is not being observed.
4.2.3 Threat Detection
4.2.3.1 The solution shall detect known and unknown threats, including malware, ransomware, command-
and-control activity, data exfiltration, insider threats and zero-day attacks.
4.2.3.2 The solution shall detect reconnaissance, credential abuse, privilege escalation and lateral
movement between hosts, segments, sites and zones.
4.2.3.3 The solution shall detect anomalous behaviour relative to learned baselines for users, devices and
network segments.
4.2.3.4 The solution shall detect policy violations and unauthorised services, protocols, connections and
shadow IT.
4.2.3.5 The solution shall assign a risk score and severity to every detection, with the underlying rationale
exposed to the analyst.
4.2.3.6 The solution shall detect threats crossing the IT and OT boundary and shall raise these with
appropriate priority.
4.2.4 Threat Hunting and Investigation
4.2.4.1 The solution shall enable analysts to proactively hunt for threats using flexible queries across live
and historical data.
4.2.4.2 The solution shall provide retrospective search across retained metadata and packet data for the full
retention period.
4.2.4.3 The solution shall reconstruct the full sequence of events for an incident, including source,
destination, protocol, timing and payload evidence where captured.
4.2.4.4 The solution shall support pivoting between entities such as host, user, IP address, domain, file hash
and session within a single investigation workflow.
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
4.3.2.3.3 The solution shall decode operational technology and industrial protocols, including Modbus/TCP,
DNP3, IEC 60870-5-104, IEC 61850 (MMS, GOOSE and Sampled Values) and OPC UA/DA, together with
any other protocols in use in the City Power operational environment.
4.3.2.3.4 Application-layer decoding and metadata extraction shall be provided, rather than port-based
classification alone.
4.3.2.3.5 Tunnelled and encapsulated traffic, including GRE, VXLAN, MPLS, IPsec and QinQ, shall be
decapsulated and analysed.
4.3.2.3.6 The Service Provider shall provide a full list of supported protocols and decoders, and shall state the
process, timeframe and cost, if any, for adding support for protocols not currently supported.
4.3.2.4 Encrypted Traffic Analysis
4.3.2.4.1 The solution shall analyse encrypted traffic without requiring decryption, using metadata, certificate
and handshake analysis and fingerprinting techniques such as JA3, JA3S and JA4.
4.3.2.4.2 Detect malicious or anomalous use of encryption, including self-signed and expired certificates, weak
cipher suites, deprecated TLS versions, domain fronting, encrypted command-and-control channels
and covert tunnelling.
4.3.2.4.3 Where decryption is required, the solution shall integrate with existing decryption or TLS inspection
infrastructure rather than mandating a proprietary approach.
4.3.2.4.4 Any decryption capability shall be selectively applicable by policy and shall be capable of excluding
categories of traffic protected under POPIA or City Power policy.
4.3.2.4.5 Detection efficacy on encrypted traffic shall be demonstrated during the proof of concept or
acceptance testing.
4.3.3 Detection Engine
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
4.3.3.2.3 The solution shall automatically match live and historical traffic against indicators of compromise,
including retrospective matching of newly received indicators against retained data.
4.3.3.2.4 Threat intelligence updates shall be delivered continuously and at no additional cost for the duration
of the contract.
4.3.3.2.5 The solution shall support intelligence confidence scoring, ageing and suppression of low-quality
indicators to limit noise.
4.3.3.3 Signature and Rule Engine
4.3.3.3.1 The solution shall provide a vendor-maintained signature and rule set that is updated continuously
for the duration of the contract.
4.3.3.3.2 The solution shall support industry-standard rule formats, such as Suricata or Snort, YARA and Sigma,
and allow City Power to author, import, test and deploy custom rules at no additional cost.
4.3.3.3.3 The solution shall provide rule versioning, staged roll-out, testing against historical data, and roll-back.
4.3.3.3.4 Signature and rule updates shall not require an outage or result in any reduction of monitoring
coverage.
4.3.3.4 MITRE ATT&CK Mapping
4.3.3.4.1 Every detection shall be mapped to the relevant MITRE ATT&CK tactic or tactics and technique or
techniques, including sub-techniques.
4.3.3.4.2 Both ATT&CK for Enterprise and ATT&CK for ICS shall be supported, in view of the City Power
operational technology environment.
4.3.3.4.3 The solution shall provide an ATT&CK coverage heat map indicating which techniques are covered,
partially covered or not covered by the deployed configuration.
4.3.3.4.4 Incidents shall present the observed attack chain mapped to the corresponding ATT&CK stages.
4.3.3.4.5 ATT&CK mappings shall be maintained current with successive releases of the framework.
4.3.3.5 Behavioural Analytics
4.3.3.5.1 The solution shall provide user and entity behaviour analytics across users, devices, service accounts
and applications.
4.3.3.5.2 The solution shall detect abnormal authentication, access, data movement, timing and volume
patterns.
4.3.3.5.3 The solution shall detect insider threat indicators, including unusual data staging, mass file access and
off-hours activity.
4.3.3.5.4 The solution shall support peer group analysis and cumulative risk scoring that aggregates related
low-severity events into a meaningful signal.
4.3.3.5.5 The solution shall correlate identity context from directory services so that activity is attributed to a
user and not only to an IP address.
4.3.3.6 Lateral Movement Detection
4.3.3.6.1 The solution shall detect lateral movement techniques, including pass-the-hash, pass-the-ticket,
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
4.3.7.1.7 The solution shall provide audit-ready reports, on demand and on schedule, evidencing monitoring
coverage, detection activity, incident handling and response times, in a form acceptable to internal
and external auditors.
4.3.7.1.8 All logs and records shall be tamper-evident and shall be retained in accordance with the retention
requirements of this specification and the City Power records retention policy.
4.3.7.1.9 Reports shall be exportable in PDF, CSV and Excel formats and shall be schedulable for automatic
distribution to nominated recipients.
4.3.7.1.10 City Power shall be able to create and modify compliance report templates without vendor
intervention or additional cost.
4.3.8 Security of the Solution
4.3.8.1.1 The solution shall enforce role-based access control and multi-factor authentication, and shall encrypt
data in transit and at rest using AES-256 or a stronger equivalent.
4.3.8.1.2 All components shall be deployed on hardened builds, and the Service Provider shall be responsible
for vulnerability and patch management of the solution for the duration of the contract.
4.3.8.1.3 The Service Provider shall provide evidence of independent security testing of the product and shall
remediate identified vulnerabilities within agreed severity-based timelines.
4.3.8.1.4 Remote access by the Service Provider for support purposes shall be brokered, logged, time-limited
and subject to prior City Power approval.
4.4 Enhancements
4.4.1 Forensic services as and when required.
4.4.2 ICT risk detection and treatment services.
4.4.3 Penetration testing.
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
5.5.7 The detection method for each incident, identifying which control detected it, and highlighting incidents
detected late or only after impact had occurred.
5.5.8 Attacker dwell time where determinable, and the mean time to detect and mean time to respond
achieved over the period.
5.5.9 Incidents that recurred or were not fully remediated, together with the underlying causes.
5.5.10 Identification of the attack types that the existing City Power controls would not have detected, and an
explanation of how the proposed solution addresses each of them.
5.5.11 Any indicators of current or historical undetected compromise identified during the assessment, which
shall be reported to City Power immediately on discovery.
5.6 Pre-Assessment Report and Acceptance
5.6.1 The findings shall be consolidated into a Pre-Assessment Report, submitted in both electronic and hard
copy.
5.6.2 The report shall include an executive summary suitable for ICT and executive management, together
with detailed findings supported by evidence and data.
5.6.3 The report shall include the analysis of the users who log on to the environment, the machine and
device inventory, and the history of attacks and their associated types, in addition to the technical
assessment for solution deployment.
5.6.4 The report shall include the confirmed solution design, bill of materials, licensing quantities,
infrastructure requirements, integration plan, implementation plan and risk register.
5.6.5 The report shall include prioritised recommendations, distinguishing between items to be addressed by
the solution, items requiring action by City Power, and items falling outside the scope of this contract.
5.6.6 The Service Provider shall present the report to City Power ICT Security and shall address any queries
arising from it.
5.6.7 The report shall be formally accepted and signed off by City Power before implementation commences,
and implementation shall not proceed on the basis of an unaccepted report.
5.6.8 The report shall be delivered within the timeframe agreed at contract award and, in any event, within
thirty (30) working days of commencement of the assessment, unless otherwise agreed in writing.
5.7 Conduct of the Assessment
5.7.1 The assessment shall be conducted passively and non-intrusively and shall not disrupt or degrade any
production, operational or substation system.
5.7.2 No active scanning, testing or other intrusive technique shall be used without prior written
authorisation from City Power and adherence to the City Power change control process.
5.7.3 All work shall be performed by suitably qualified and vetted personnel, and the Service Provider shall
provide the names, qualifications and security clearance status of assessment personnel in advance.
5.7.4 All data obtained during the assessment shall be treated as confidential, shall be processed in
accordance with POPIA, shall not be removed from the City Power environment without authorisation,
and shall be securely destroyed or returned on completion, with written confirmation of destruction
provided.
5.7.5 The Service Provider shall not disclose the findings of the assessment to any third party.
5.7.6 City Power shall provide reasonable access to the environment, documentation, personnel and log data
required for the assessment.
5.7.7 Where the assessment identifies a material change to scope, sizing or price, this shall be raised in writing
and agreed before implementation; no variation shall be claimed in respect of items that a competent
bidder ought reasonably to have allowed for.
transportation, and disposal. Guidance on the requirements for a quality management system may be found in
the following standards: ISO 9001:2015. The details shall be subject to an agreement between the purchaser
and the supplier.
Pricing Schedule
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
1.4.2 Deliver ongoing technical support, maintenance, updates, and patches to ensure optimal system
performance and security effectiveness.
1.5 Secure Operational Environment
1.5.1 Ensure the solution operates within a secure and compliant environment, aligned with City Power’s
4.3.3.7.3 The solution shall provide alert deduplication and correlation so that a single incident does not
generate repeated or fragmented alerts.
4.3.3.7.4 The solution shall provide analyst feedback mechanisms, such as true and false positive marking, that
measurably improve subsequent detection quality.
4.3.3.7.5 The solution shall report on detection quality metrics, including alert volumes, false positive rates and
time to triage.
4.3.3.7.6 A dedicated tuning and optimisation period shall be included in the implementation, and the Service
Compliance Requirements
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)4.1 General Requirements The following requirements shall be considered in the proposal to strengthen City Power security: 4.1.1 Network Detection and Response (NDR) solution 4.1.2 Turnkey delivery of the NDR solution, inclusive of all hardware, software, licensing, integration, commissioning, documentation, training and support. 4.1.3 A mandatory pre-deployment assessment of the City Power environment, as set out in the Pre- Deployment Assessment section of this specification. 4.1.4 Full compliance with the Functional Requirements and the Technical Requirements set out below. 4.2 Functional Requirements The functional requirements set out below describe what the solution shall do in operational use. The Service Provider shall indicate compliance with each requirement as Fully Compliant, Partially Compliant or Not Compliant, and shall substantiate every response. Failure to meet a mandatory requirement may render a bid non-responsive. 4.2.1 Turnkey Solution Delivery 4.2.1.1 The solution shall be delivered as a complete turnkey solution, with the Service Provider accountable for design, supply, delivery, installation, configuration, integration, testing, commissioning, documentation, training, handover and support. 4.2.1.2 The Service Provider shall supply all hardware, software, licences, subscriptions, connectors and ancillary components required for the solution to operate at the required capacity. 4.2.1.3 The Service Provider shall provide all professional services required to place the solution into full production use, including project management, design workshops, migration and cut-over. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.2.1.4 Any item not expressly listed in this specification but reasonably necessary for the correct and complete functioning of the solution shall be deemed to be included in the Service Provider's offer. 4.2.1.5 The Service Provider shall provide a documented implementation plan with milestones, deliverables, dependencies, resource allocations and acceptance criteria. 4.2.1.6 Formal acceptance testing shall be conducted against agreed criteria and signed off by City Power before the solution is regarded as commissioned. 4.2.2 Network Visibility and Monitoring 4.2.2.1 The solution shall continuously monitor and analyse both north-south and east-west traffic across the corporate, data centre, cloud and operational technology environments. 4.2.2.2 The solution shall provide continuous, passive monitoring that does not degrade network performance, latency or availability. 4.2.2.3 The solution shall automatically discover, classify and profile all devices communicating on the monitored networks, including unmanaged, IoT and OT devices. 4.2.2.4 The solution shall maintain an up-to-date inventory of monitored assets, exportable and reconcilable against the City Power CMDB and asset register. 4.2.2.5 The solution shall present real-time and historical views of network communications, including peer relationships, protocols, volumes, directions and session detail. 4.2.2.6 The solution shall identify and report on blind spots where traffic is not being observed. 4.2.3 Threat Detection 4.2.3.1 The solution shall detect known and unknown threats, including malware, ransomware, command- and-control activity, data exfiltration, insider threats and zero-day attacks. 4.2.3.2 The solution shall detect reconnaissance, credential abuse, privilege escalation and lateral movement between hosts, segments, sites and zones. 4.2.3.3 The solution shall detect anomalous behaviour relative to learned baselines for users, devices and network segments. 4.2.3.4 The solution shall detect policy violations and unauthorised services, protocols, connections and shadow IT. 4.2.3.5 The solution shall assign a risk score and severity to every detection, with the underlying rationale exposed to the analyst. 4.2.3.6 The solution shall detect threats crossing the IT and OT boundary and shall raise these with appropriate priority. 4.2.4 Threat Hunting and Investigation 4.2.4.1 The solution shall enable analysts to proactively hunt for threats using flexible queries across live and historical data. 4.2.4.2 The solution shall provide retrospective search across retained metadata and packet data for the full retention period. 4.2.4.3 The solution shall reconstruct the full sequence of events for an incident, including source, destination, protocol, timing and payload evidence where captured. 4.2.4.4 The solution shall support pivoting between entities such as host, user, IP address, domain, file hash and session within a single investigation workflow. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.2.4.5 The solution shall allow hunting hypotheses and queries to be saved, shared and converted into custom detections. 4.2.4.6 The solution shall provide guided investigation workflows to support analysts of varying experience levels. 4.2.5 Alerting, Triage and Case Management 4.2.5.1 The solution shall generate prioritised, deduplicated and correlated alerts, grouping related detections into a single incident. 4.2.5.2 The solution shall provide a case management capability enabling incidents to be created, assigned, tracked, escalated, annotated and closed with disposition codes. 4.2.5.3 The solution shall maintain a complete, tamper-evident audit trail of all analyst actions taken on a case. 4.2.5.4 The solution shall support configurable notification by email and SMS and through integration with City Power's service management and collaboration platforms. 4.2.5.5 The solution shall track and report incident lifecycle metrics, including mean time to detect and mean time to respond. 4.2.6 Response and Containment 4.2.6.1 The solution shall support both automated and analyst-initiated response actions, including host isolation, session termination, blocking and quarantine, through integration with NGFW, NAC, EDR and directory services. 4.2.6.2 The solution shall allow response playbooks to be configured, tested and executed, with approval gates where required. 4.2.6.3 The solution shall ensure that no automated response action is applied to operational technology or critical operational systems without explicit prior authorisation by City Power. 4.2.6.4 The solution shall log every response action taken, whether automated or manual, together with the initiating rule or user and the outcome. 4.2.6.5 The solution shall support safe roll-back of response actions where a detection is subsequently found to be a false positive. 4.2.7 Reporting and Dashboards 4.2.7.1 The solution shall provide role-based dashboards suitable for executives, ICT management, SOC analysts and auditors. 4.2.7.2 The solution shall provide scheduled and on-demand reporting in at least PDF, CSV and Excel formats. 4.2.7.3 The solution shall provide standard reports covering threat activity, incident trends, asset risk, detection coverage and compliance posture. 4.2.7.4 The solution shall allow custom reports and dashboards to be built and modified by City Power without vendor intervention or additional cost. 4.2.8 Administration and Access Control 4.2.8.1 The solution shall provide role-based access control with granular permissions, integrated with City Power's directory service. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.2.8.2 The solution shall enforce multi-factor authentication for all administrative and analyst access. 4.2.8.3 The solution shall maintain a complete audit log of all configuration changes, logons and data access within the solution. 4.2.8.4 The solution shall support configuration backup and restore, and disaster recovery of the solution itself. 4.2.9 Availability, Data Handling and Retention 4.2.9.1 The solution shall retain detection metadata and incident records for a minimum of twelve (12) months, and packet or metadata evidence in accordance with the retention requirements of this specification. 4.2.9.2 The solution shall ensure that all data collected, processed and stored is handled in accordance with POPIA and City Power's information security policies. 4.2.9.3 The solution shall provide high availability for all critical components, with no single point of failure. 4.2.9.4 The solution shall support secure export of evidence in standard formats suitable for forensic and legal use, preserving chain-of-custody integrity. 4.2.10 Knowledge Transfer and Operational Handover 4.2.10.1 The Service Provider shall provide a documented operational handover, including run-books, standard operating procedures and an escalation matrix. 4.2.10.2 The Service Provider shall ensure that City Power personnel are able to independently operate, tune and administer the solution on completion of handover. 4.2.10.3 The Service Provider shall provide as-built documentation accurately reflecting the deployed configuration. 4.3 Technical requirements 4.3.1 Network Detection and Response (NDR) solution A security solution that analyses raw network traffic, flow records, and metadata using AI and behavioural analytics to detect, investigate, and respond to malicious activity. They provide comprehensive visibility into both north-south and east-west traffic, allowing security teams to identify threats that bypass traditional perimeter defences. Key Components and Capabilities 4.3.1.1 Behavioural Analysis & AI: Identifies anomalies in normal network patterns, including insider threats and zero-day attacks. 4.3.1.2 Traffic Analysis: Monitors network traffic, focusing on metadata to analyse encrypted traffic without decryption. 4.3.1.3 Rapid Response: Automates security actions to stop threats in real-time. 4.3.2 Data Collection Layer The Service Provider shall deliver a data collection layer that provides complete, continuous and non- disruptive visibility of all monitored environments. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.2.1 Traffic Visibility 4.3.2.1.1 The solution shall collect traffic from SPAN or mirror ports on all core and distribution switches, and from network TAPs at critical aggregation points, data centre interconnects and the internet edge. 4.3.2.1.2 The solution shall collect cloud workload traffic, including through virtual private cloud (VPC) traffic mirroring for cloud-hosted environments. 4.3.2.1.3 The solution shall ingest flow logs from Microsoft Azure (NSG and VNet flow logs) and Amazon Web Services (VPC flow logs), together with NetFlow, sFlow, IPFIX and J-Flow records from network devices. 4.3.2.1.4 The solution shall collect host-level telemetry from servers using eBPF-based sensors, or equivalent kernel-level agents, providing process-to-connection attribution on Linux, with equivalent supported sensors for Windows servers. 4.3.2.1.5 The solution shall collect traffic from remote sites, VPN concentrators and remote access gateways. 4.3.2.1.6 The solution shall collect operational technology and substation network traffic passively and without any impact on operational systems. 4.3.2.1.7 The solution shall provide visibility of east-west traffic between virtual machines within hypervisor environments. 4.3.2.1.8 The Service Provider shall confirm all required collection points during the pre-deployment assessment and shall specify any additional aggregation, packet broker or optical infrastructure required. 4.3.2.2 Packet Capture and Retention 4.3.2.2.1 The solution shall support full packet capture (PCAP) at monitored collection points or, as a minimum, full protocol metadata extraction where full PCAP is not practicable. 4.3.2.2.2 Where full PCAP is provided, capture shall be continuous and shall additionally be triggerable on detection to capture extended context around an event. 4.3.2.2.3 Packet or metadata retention shall be a minimum of thirty (30) days, and the solution shall be sized and licensed to support a target retention of ninety (90) days. 4.3.2.2.4 Enriched metadata and detection records shall be retained for a minimum of twelve (12) months to support trend analysis and compliance reporting. 4.3.2.2.5 Retained data shall remain searchable and retrievable for the full retention period without restoration delays that would impede an investigation. 4.3.2.2.6 The Service Provider shall state the storage volumes, storage type, and any compression or roll-off behaviour on which the stated retention periods are based. 4.3.2.2.7 Storage shall be expandable to extend retention without replacement of the deployed platform, and the incremental cost shall be stated. 4.3.2.2.8 Captured data shall be encrypted at rest, and all access to it shall be restricted by role and logged. 4.3.2.3 Protocol Support 4.3.2.3.1 The solution shall decode and extract metadata from information technology protocols, including DNS, HTTP, HTTPS/TLS, SMB/CIFS, LDAP and LDAPS, Kerberos, RDP, SSH, FTP and SFTP, SMTP, IMAP, POP3, NTP, DHCP, SNMP, ICMP, SIP and common database protocols. 4.3.2.3.2 Directory, authentication and remote access protocols shall be parsed to the level required to establish user, host and session context. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.2.3.3 The solution shall decode operational technology and industrial protocols, including Modbus/TCP, DNP3, IEC 60870-5-104, IEC 61850 (MMS, GOOSE and Sampled Values) and OPC UA/DA, together with any other protocols in use in the City Power operational environment. 4.3.2.3.4 Application-layer decoding and metadata extraction shall be provided, rather than port-based classification alone. 4.3.2.3.5 Tunnelled and encapsulated traffic, including GRE, VXLAN, MPLS, IPsec and QinQ, shall be decapsulated and analysed. 4.3.2.3.6 The Service Provider shall provide a full list of supported protocols and decoders, and shall state the process, timeframe and cost, if any, for adding support for protocols not currently supported. 4.3.2.4 Encrypted Traffic Analysis 4.3.2.4.1 The solution shall analyse encrypted traffic without requiring decryption, using metadata, certificate and handshake analysis and fingerprinting techniques such as JA3, JA3S and JA4. 4.3.2.4.2 Detect malicious or anomalous use of encryption, including self-signed and expired certificates, weak cipher suites, deprecated TLS versions, domain fronting, encrypted command-and-control channels and covert tunnelling. 4.3.2.4.3 Where decryption is required, the solution shall integrate with existing decryption or TLS inspection infrastructure rather than mandating a proprietary approach. 4.3.2.4.4 Any decryption capability shall be selectively applicable by policy and shall be capable of excluding categories of traffic protected under POPIA or City Power policy. 4.3.2.4.5 Detection efficacy on encrypted traffic shall be demonstrated during the proof of concept or acceptance testing. 4.3.3 Detection Engine The detection engine shall combine multiple, complementary detection methods so that the solution is not dependent on any single technique. 4.3.3.1 Artificial Intelligence and Machine Learning Anomaly Detection 4.3.3.1.1 The solution shall establish and continuously maintain behavioural baselines for every user, device, application and network segment. 4.3.3.1.2 The solution shall detect statistically significant deviations from baseline without reliance on signatures. 4.3.3.1.3 Models shall self-tune as the environment changes, and the Service Provider shall state the required learning period before the solution reaches full effectiveness. 4.3.3.1.4 Detections shall be explainable, with the analyst able to see which features and observations drove the score. 4.3.3.1.5 The Service Provider shall confirm whether models are trained locally, in the cloud or both, and shall confirm that no City Power data is transferred outside the Republic of South Africa without prior written authorisation. 4.3.3.2 Threat Intelligence Feeds 4.3.3.2.1 The solution shall ingest commercial, open-source, government and sector-specific (including electricity utility sector) threat intelligence, as well as City Power-specific indicators. 4.3.3.2.2 The solution shall support STIX and TAXII, MISP and custom feed formats, together with manual indicator upload. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.3.2.3 The solution shall automatically match live and historical traffic against indicators of compromise, including retrospective matching of newly received indicators against retained data. 4.3.3.2.4 Threat intelligence updates shall be delivered continuously and at no additional cost for the duration of the contract. 4.3.3.2.5 The solution shall support intelligence confidence scoring, ageing and suppression of low-quality indicators to limit noise. 4.3.3.3 Signature and Rule Engine 4.3.3.3.1 The solution shall provide a vendor-maintained signature and rule set that is updated continuously for the duration of the contract. 4.3.3.3.2 The solution shall support industry-standard rule formats, such as Suricata or Snort, YARA and Sigma, and allow City Power to author, import, test and deploy custom rules at no additional cost. 4.3.3.3.3 The solution shall provide rule versioning, staged roll-out, testing against historical data, and roll-back. 4.3.3.3.4 Signature and rule updates shall not require an outage or result in any reduction of monitoring coverage. 4.3.3.4 MITRE ATT&CK Mapping 4.3.3.4.1 Every detection shall be mapped to the relevant MITRE ATT&CK tactic or tactics and technique or techniques, including sub-techniques. 4.3.3.4.2 Both ATT&CK for Enterprise and ATT&CK for ICS shall be supported, in view of the City Power operational technology environment. 4.3.3.4.3 The solution shall provide an ATT&CK coverage heat map indicating which techniques are covered, partially covered or not covered by the deployed configuration. 4.3.3.4.4 Incidents shall present the observed attack chain mapped to the corresponding ATT&CK stages. 4.3.3.4.5 ATT&CK mappings shall be maintained current with successive releases of the framework. 4.3.3.5 Behavioural Analytics 4.3.3.5.1 The solution shall provide user and entity behaviour analytics across users, devices, service accounts and applications. 4.3.3.5.2 The solution shall detect abnormal authentication, access, data movement, timing and volume patterns. 4.3.3.5.3 The solution shall detect insider threat indicators, including unusual data staging, mass file access and off-hours activity. 4.3.3.5.4 The solution shall support peer group analysis and cumulative risk scoring that aggregates related low-severity events into a meaningful signal. 4.3.3.5.5 The solution shall correlate identity context from directory services so that activity is attributed to a user and not only to an IP address. 4.3.3.6 Lateral Movement Detection 4.3.3.6.1 The solution shall detect lateral movement techniques, including pass-the-hash, pass-the-ticket, Kerberoasting, golden and silver ticket use, remote service creation, WMI and PsExec-style remote execution, RDP and SSH chaining, SMB administrative share access and living-off-the-land activity. 4.3.3.6.2 The solution shall detect internal reconnaissance and scanning, including port, service, share and directory enumeration. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.3.6.3 The solution shall detect east-west movement across VLANs, segments and sites, and specifically across the IT and OT boundary, flagging any traffic that crosses a segmentation boundary in violation of policy. 4.3.3.6.4 The solution shall visualise the lateral movement path across hosts and accounts on a timeline, showing the chain from initial foothold to current position. 4.3.3.6.5 The solution shall detect anomalous use of administrative and service accounts across multiple hosts. 4.3.3.6.6 Related lateral movement detections shall be correlated into a single incident rather than raised as isolated alerts for each hop. 4.3.3.7 Detection Accuracy and Management of False Positives 4.3.3.7.1 The solution shall be tuned to deliver a low false positive rate, and the Service Provider shall state the expected false positive rate together with the basis for that figure. 4.3.3.7.2 The solution shall provide tuning capabilities including allow-listing, exception handling, environment- specific baselines, alert suppression and threshold adjustment, all of which shall be performable by City Power without vendor intervention or additional cost. 4.3.3.7.3 The solution shall provide alert deduplication and correlation so that a single incident does not generate repeated or fragmented alerts. 4.3.3.7.4 The solution shall provide analyst feedback mechanisms, such as true and false positive marking, that measurably improve subsequent detection quality. 4.3.3.7.5 The solution shall report on detection quality metrics, including alert volumes, false positive rates and time to triage. 4.3.3.7.6 A dedicated tuning and optimisation period shall be included in the implementation, and the Service Provider shall conduct tuning reviews at least quarterly for the duration of the contract at no additional cost. 4.3.3.7.7 The Service Provider shall commit to a sustained alert volume that is within the reasonable handling capacity of the City Power security operations function, as agreed during implementation. 4.3.4 Response and Integration The solution shall integrate with the wider City Power security ecosystem and shall not operate as an isolated point product. 4.3.4.1 SIEM Integration 4.3.4.1.1 The solution shall provide native, bi-directional integration with the City Power SIEM platform. 4.3.4.1.2 The solution shall forward alerts, enriched metadata and raw or summarised logs in standard formats, including CEF, LEEF, Syslog and JSON, with configurable verbosity. 4.3.4.1.3 The solution shall preserve full context in forwarded records and provide a link from the SIEM record back to the source detection and supporting evidence. 4.3.4.1.4 The solution shall support field normalisation to a common schema to simplify correlation with other data sources. 4.3.4.1.5 The Service Provider shall configure, test and document the SIEM integration as part of the implementation, at no additional cost. 4.3.4.2 API Access STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.4.2.1 The solution shall provide a fully documented, versioned REST API, and a streaming interface where available, giving access to alerts, incidents, assets, metadata, detections, configuration and reporting. 4.3.4.2.2 The API shall support both read and write operations, including the creation and update of cases and the triggering of response actions. 4.3.4.2.3 Authentication shall be by token or certificate, with role-scoped API credentials, disclosed rate limits and full audit logging of API activity. 4.3.4.2.4 API documentation and any software development kits shall be provided to City Power at no additional cost, and API access shall be included in the licensing. 4.3.4.2.5 The Service Provider shall state its policy on backward compatibility and the notice period given before deprecation of API versions. 4.3.4.3 Case Management 4.3.4.3.1 The solution shall provide native case management, including creation, assignment, prioritisation, SLA tracking, escalation, evidence attachment, analyst notes, linking of related cases and closure with disposition codes. 4.3.4.3.2 The solution shall support customisable workflows and case states aligned to the City Power incident response process. 4.3.4.3.3 The solution shall integrate with the City Power IT service management platform to allow bi- directional synchronisation of tickets. 4.3.4.3.4 The solution shall maintain a complete and immutable audit trail for each case, suitable for use as evidence. 4.3.4.3.5 The solution shall provide case metrics and reporting, including mean time to detect, mean time to respond, backlog and analyst workload. 4.3.4.4 SOAR Integration 4.3.4.4.1 The solution shall integrate with the existing or future City Power SOAR platform, or provide equivalent native orchestration and automation capability. 4.3.4.4.2 The solution shall provide pre-built connectors and playbooks for common enrichment and containment actions. 4.3.4.4.3 The solution shall support automated enrichment on alert creation, including threat intelligence lookup, asset and identity context and sandbox detonation. 4.3.4.4.4 The solution shall support automated containment with configurable approval gates, and mandatory manual approval for any action affecting operational technology or critical systems. 4.3.4.4.5 Playbooks shall be editable by City Power, version-controlled, and testable in a non-production mode before deployment. 4.3.4.4.6 The Service Provider shall list all supported integrations with security and network products and shall confirm compatibility with the incumbent City Power NGFW, NAC, EDR, email security and directory platforms, as verified during the pre-deployment assessment. 4.3.5 Deployment and Scalability The solution shall be capable of deployment in a manner that suits the City Power environment and shall scale with the organisation over the contract term. 4.3.5.1 Cloud-Native Architecture STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.5.1.1 The solution shall be cloud-native in design, based on containerised microservices, capable of horizontal scaling and supporting automated deployment and upgrade. 4.3.5.1.2 The solution shall support monitoring of workloads in Microsoft Azure and Amazon Web Services, including native integration with cloud flow logs and traffic mirroring services. 4.3.5.1.3 The solution shall provide unified visibility and a single management plane across on-premises, cloud and hybrid environments. 4.3.5.1.4 The solution shall support segregation of data and views by site, business unit or environment where required. 4.3.5.2 Throughput and Capacity 4.3.5.2.1 The solution shall be sized for peak traffic and not average traffic and shall sustain peak throughput without packet loss or any reduction in detection capability. 4.3.5.2.2 The Service Provider shall state the rated throughput of each sensor and of the aggregate deployment, expressed both in Gbps and in flows or events per second. 4.3.5.2.3 Sizing shall include a minimum of thirty percent (30%) headroom above the current measured peak traffic and shall accommodate a stated growth rate over the contract term. 4.3.5.2.4 Final sizing shall be confirmed against the traffic volumes actually measured during the pre- deployment assessment. 4.3.5.2.5 The Service Provider shall state any performance impact on monitored systems and networks and shall confirm that collection is passive. 4.3.5.2.6 Capacity shall be expandable by the addition of sensors or nodes without redesign or wholesale replacement, and the incremental cost shall be stated. 4.3.5.2.7 Licensing shall be transparent; the Service Provider shall state the licensing metric applied, whether bandwidth, sensors, assets, users or data volume, and shall state the behaviour of the solution should a licensed limit be exceeded. 4.3.5.3 Deployment Options 4.3.5.3.1 The solution shall support deployment on-premises as a physical appliance, as a virtual appliance or virtual machine on the City Power hypervisor platform, as a cloud SaaS service, or as a hybrid combination of these. 4.3.5.3.2 The Service Provider shall recommend the deployment model best suited to the City Power environment, with justification, and shall price both the recommended model and the alternatives. 4.3.5.3.3 Where a SaaS or cloud-hosted component is proposed, the Service Provider shall state the hosting location and shall comply with POPIA requirements on data residency and cross-border transfer; personal information shall be hosted within the Republic of South Africa unless expressly authorised in writing by City Power. 4.3.5.3.4 Migration between deployment models during the contract shall be possible without loss of historical data or additional licensing cost. 4.3.5.3.5 All components shall support high availability and, where applicable, shall integrate with the City Power disaster recovery arrangements. 4.3.5.3.6 Sensors shall continue to collect and buffer data during loss of connectivity to the management plane and shall forward buffered data on restoration. 4.3.6 Infrastructure Requirements STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 The Service Provider shall specify in full the infrastructure required to deliver the solution and shall clearly distinguish between items it will supply as part of the turnkey solution and any items to be provided by City Power. Any item required for the solution to function that is not expressly identified as a City Power responsibility shall be deemed to be included in the Service Provider's offer. The Service Provider shall state, as a minimum: 4.3.6.1.1 A complete bill of materials listing all hardware, appliances, sensors, collectors, aggregation devices, packet brokers, TAPs, optics and transceivers, cabling and mounting hardware. 4.3.6.1.2 Compute requirements for each component, including CPU cores, memory and the hypervisor platforms and versions supported. 4.3.6.1.3 Storage requirements, including capacity, storage type, IOPS and throughput, together with the basis of the calculation against the required retention periods. 4.3.6.1.4 Network requirements, including the number, speed and type of interfaces, VLANs, IP addressing, routing, and the firewall rules and ports required between components. 4.3.6.1.5 Rack space in rack units, power in kilowatts and feed type, redundancy and cooling requirements at each site. 4.3.6.1.6 Operating system, database and any third-party software required, and confirmation of whether the associated licences are included in the offer. 4.3.6.1.7 Time synchronisation and DNS requirements, including NTP source and accuracy. 4.3.6.1.8 Certificate, public key infrastructure and directory integration requirements. 4.3.6.1.9 Requirements at each site where sensors are to be deployed, including substations and remote sites. 4.3.6.1.10 Environmental and physical requirements for equipment to be installed in operational or substation environments, including operating temperature range and ingress protection rating. 4.3.6.1.11 Backup, restore and disaster recovery infrastructure for the solution itself. 4.3.6.1.12 Bandwidth required between sensors, collectors and the analysis platform, and between on-premises components and any cloud-hosted component. 4.3.6.1.13 Additional infrastructure required to support the stated growth over the contract term. 4.3.6.1.14 Final infrastructure requirements shall be confirmed in the Pre-Assessment Report, and any material deviation from the tendered bill of materials shall be subject to the prior written approval of City Power. 4.3.7 Compliance and Regulatory Reporting 4.3.7.1.1 The solution and its implementation shall comply with the Protection of Personal Information Act, 2013 (POPIA), and the Service Provider shall describe how personal information captured in network traffic is identified, minimised, masked, protected and lawfully processed. 4.3.7.1.2 The solution shall provide POPIA-aligned reporting, including the evidence required to support notification of a security compromise to the Information Regulator and to affected data subjects. 4.3.7.1.3 The solution shall provide reporting mapped to ISO/IEC 27001:2022, including the Annex A controls relevant to monitoring, logging, threat intelligence, network security and information security incident management, in support of the City Power information security management system. 4.3.7.1.4 The solution shall provide reporting aligned to ISO/IEC 27002:2022 control guidance and to ISO/IEC 27035 information security incident management practice. 4.3.7.1.5 The solution shall provide reporting mapped to the MITRE ATT&CK framework and, where applicable, to the functions of the NIST Cybersecurity Framework. 4.3.7.1.6 The solution shall provide reporting to support King IV and COBIT governance, risk and assurance reporting requirements. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 4.3.7.1.7 The solution shall provide audit-ready reports, on demand and on schedule, evidencing monitoring coverage, detection activity, incident handling and response times, in a form acceptable to internal and external auditors. 4.3.7.1.8 All logs and records shall be tamper-evident and shall be retained in accordance with the retention requirements of this specification and the City Power records retention policy. 4.3.7.1.9 Reports shall be exportable in PDF, CSV and Excel formats and shall be schedulable for automatic distribution to nominated recipients. 4.3.7.1.10 City Power shall be able to create and modify compliance report templates without vendor intervention or additional cost. 4.3.8 Security of the Solution 4.3.8.1.1 The solution shall enforce role-based access control and multi-factor authentication, and shall encrypt data in transit and at rest using AES-256 or a stronger equivalent. 4.3.8.1.2 All components shall be deployed on hardened builds, and the Service Provider shall be responsible for vulnerability and patch management of the solution for the duration of the contract. 4.3.8.1.3 The Service Provider shall provide evidence of independent security testing of the product and shall remediate identified vulnerabilities within agreed severity-based timelines. 4.3.8.1.4 Remote access by the Service Provider for support purposes shall be brokered, logged, time-limited and subject to prior City Power approval. 4.4 Enhancements The Service Provider shall provide enhancements, support, and maintenance services for existing and future ICT Security solutions. The enhancements shall be provided as and when needed. 4.4.1 Forensic services as and when required. 4.4.2 ICT risk detection and treatment services. 4.4.3 Penetration testing.
PRE-DEPLOYMENT ASSESSMENT A pre-deployment assessment shall be undertaken by the appointed Service Provider before the final solution design, sizing, licensing and deployment plan are confirmed. The assessment is a mandatory deliverable, and it shall be completed and formally accepted by City Power before implementation commences. The cost of the assessment shall be included in the Service Provider's turnkey price and shall not be charged as a separate variation. 5.1 Objectives of the Assessment The objectives of the assessment shall be to: 5.1.1 Establish an accurate, evidence-based understanding of the City Power ICT and operational technology environment. 5.1.2 Confirm the technical requirements for deploying the solution, including collection points, sizing, infrastructure and integration effort. 5.1.3 Establish a baseline of user, device and threat activity against which the effectiveness of the solution can subsequently be measured. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 5.1.4 Identify risks, constraints and dependencies that may affect deployment. 5.1.5 Confirm the final bill of materials, licensing quantities and implementation plan. 5.2 Technical Assessment for Solution Deployment The technical assessment shall include, as a minimum: 5.2.1 Review of the network architecture and topology, covering the core, distribution and access layers, data centres, DMZ, remote sites, substations, cloud environments and OT networks. 5.2.2 Identification of all required collection points, including SPAN and mirror ports, TAP locations, packet broker requirements, cloud mirroring and flow log sources, and server sensor coverage. 5.2.3 Measurement of current traffic volumes and peaks at each collection point, together with the growth trend, in order to confirm sensor sizing and licensing quantities. 5.2.4 Assessment of the segmentation model and the IT and OT boundary, and identification of blind spots where traffic is currently not visible. 5.2.5 Assessment of the existing security toolset, including SIEM, SOAR, NGFW, NAC, EDR, email security and directory services, and the integration effort required for each. 5.2.6 Assessment of available infrastructure, including rack space, power, cooling, compute, storage, virtualisation and network capacity, and identification of any shortfalls. 5.2.7 Assessment of the cloud environments in use, including subscriptions, VPCs and VNets, workloads, and the flow log and traffic mirroring capability available in each. 5.2.8 Confirmation of the protocols in use, including operational technology protocols, and confirmation that the proposed solution decodes each of them. 5.2.9 Identification of constraints, change control requirements, outage windows and operational risks associated with deployment. 5.2.10 A proposed deployment architecture, phased implementation plan and cut-over approach. 5.3 User and Access Analysis The assessment shall establish which users actually log on to and use the environment, as distinct from the accounts that merely exist within it. The analysis shall report, as a minimum: 5.3.1 The total number of user accounts in the directory, and the number of those accounts that have actually authenticated during the assessment period. 5.3.2 A breakdown of active, inactive, dormant, disabled, expired and stale accounts, with the dormancy thresholds applied clearly stated. 5.3.3 Identification and count of privileged and administrative accounts, and of the individuals who actually make use of them. 5.3.4 Identification and count of service, application, shared and generic accounts, together with their usage patterns and the systems on which they are used. 5.3.5 Identification of third-party, vendor, contractor and remote support accounts, and the access held by each. 5.3.6 Logon patterns and volumes, including logon counts per user, peak and average concurrent sessions, logon times and days, and off-hours activity. 5.3.7 Logon locations and methods, distinguishing on-premises, remote and VPN, and cloud access, and identifying the devices used. 5.3.8 Identification of accounts exhibiting anomalous behaviour, including concentrations of failed logons, improbable travel, multiple simultaneous sessions, and accounts logging on to an unusually large number of machines. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 5.3.9 Accounts that have never logged on, and accounts belonging to individuals who have left the organisation. 5.3.10 A reconciliation of active accounts against the human resources establishment in order to identify orphaned accounts. 5.3.11 Where personal information is processed in the course of this analysis, it shall be handled strictly in accordance with POPIA and City Power policy. 5.4 Device and Machine Inventory The assessment shall establish how many machines are present and communicating in the environment. The inventory shall report, as a minimum: 5.4.1 The total count of devices observed on the network, broken down by type, including workstations, laptops, physical and virtual servers, network devices, security appliances, printers, mobile devices, IoT devices and OT or ICS devices. 5.4.2 Counts per site, per network segment and per environment, distinguishing corporate, data centre, cloud and operational technology environments. 5.4.3 The operating system and version distribution, including unsupported and end-of-life systems. 5.4.4 Identification of unmanaged, unknown, rogue or unauthorised devices, and of devices not recorded in the CMDB or asset register. 5.4.5 The count of virtual machines and cloud workloads, per platform. 5.4.6 Identification of devices with no endpoint protection or monitoring agent installed. 5.4.7 Device-to-user mapping where determinable, and identification of devices used by multiple users. 5.4.8 A reconciliation of the observed device count against the City Power asset register and CMDB, with discrepancies quantified. 5.4.9 The resulting device count shall be used to confirm licensing quantities where the licensing metric is asset-based. 5.5 Historical Attack and Incident Analysis The assessment shall include an analysis of the attacks that City Power has experienced, covering a period of not less than the preceding twelve (12) months, based on available logs, security tooling data, incident records and any other evidence made available by City Power. The analysis shall report, as a minimum: 5.5.1 The total number of security incidents and attempted attacks recorded over the period, with the monthly trend. 5.5.2 A breakdown of attacks by type, including as a minimum phishing and business email compromise, malware, ransomware, credential attacks such as brute force, password spraying and credential stuffing, exploitation of vulnerabilities, web application attacks, denial-of-service, insider misuse, data exfiltration attempts, lateral movement, command-and-control activity and unauthorised access attempts. 5.5.3 Mapping of the observed attacks to MITRE ATT&CK tactics and techniques. 5.5.4 The sources of attacks, including geographic origin, whether internal or external, and the identification of repeat sources. 5.5.5 The targets of attacks, including the users, systems, applications, network segments and sites most frequently targeted. 5.5.6 The severity distribution of the incidents recorded and the business impact of each. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 5.5.7 The detection method for each incident, identifying which control detected it, and highlighting incidents detected late or only after impact had occurred. 5.5.8 Attacker dwell time where determinable, and the mean time to detect and mean time to respond achieved over the period. 5.5.9 Incidents that recurred or were not fully remediated, together with the underlying causes. 5.5.10 Identification of the attack types that the existing City Power controls would not have detected, and an explanation of how the proposed solution addresses each of them. 5.5.11 Any indicators of current or historical undetected compromise identified during the assessment, which shall be reported to City Power immediately on discovery. 5.6 Pre-Assessment Report and Acceptance 5.6.1 The findings shall be consolidated into a Pre-Assessment Report, submitted in both electronic and hard copy. 5.6.2 The report shall include an executive summary suitable for ICT and executive management, together with detailed findings supported by evidence and data. 5.6.3 The report shall include the analysis of the users who log on to the environment, the machine and device inventory, and the history of attacks and their associated types, in addition to the technical assessment for solution deployment. 5.6.4 The report shall include the confirmed solution design, bill of materials, licensing quantities, infrastructure requirements, integration plan, implementation plan and risk register. 5.6.5 The report shall include prioritised recommendations, distinguishing between items to be addressed by the solution, items requiring action by City Power, and items falling outside the scope of this contract. 5.6.6 The Service Provider shall present the report to City Power ICT Security and shall address any queries arising from it. 5.6.7 The report shall be formally accepted and signed off by City Power before implementation commences, and implementation shall not proceed on the basis of an unaccepted report. 5.6.8 The report shall be delivered within the timeframe agreed at contract award and, in any event, within thirty (30) working days of commencement of the assessment, unless otherwise agreed in writing. 5.7 Conduct of the Assessment 5.7.1 The assessment shall be conducted passively and non-intrusively and shall not disrupt or degrade any production, operational or substation system. 5.7.2 No active scanning, testing or other intrusive technique shall be used without prior written authorisation from City Power and adherence to the City Power change control process. 5.7.3 All work shall be performed by suitably qualified and vetted personnel, and the Service Provider shall provide the names, qualifications and security clearance status of assessment personnel in advance. 5.7.4 All data obtained during the assessment shall be treated as confidential, shall be processed in accordance with POPIA, shall not be removed from the City Power environment without authorisation, and shall be securely destroyed or returned on completion, with written confirmation of destruction provided. 5.7.5 The Service Provider shall not disclose the findings of the assessment to any third party. 5.7.6 City Power shall provide reasonable access to the environment, documentation, personnel and log data required for the assessment. 5.7.7 Where the assessment identifies a material change to scope, sizing or price, this shall be raised in writing and agreed before implementation; no variation shall be claimed in respect of items that a competent bidder ought reasonably to have allowed for. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26
TRAINING 6.1 City Power requires the necessary training for system administrators at no cost to City Power. 6.2 The Service Provider shall clearly outline the layout of the recommended enhanced training at no cost. 6.3 The solution provider shall work closely with City Power’s resources during the implementation in a live environment to ensure practical knowledge transfer. 6.4 Training shall be on-site and form part of the implementation process. 6.5 The Service Provider shall also be required to provide training to City Power technical representatives on the system when enhanced features and functionality become available as the system is upgraded at no cost. 6.6 The suppliers shall provide technical support on system and equipment queries for the duration of the contract as of the go-live date of the implemented solution at no cost.
SUPPORT AND MAINTENANCE The Service Provider shall provide support and maintenance services on the proposed solution. 7.1 SUPPORT DESK 7.1.1 The Service Provider shall provide the Support Centre, which shall be a single point of contact for the resolution of system problems. 7.1.2 Support requests shall be submitted by phone, email, or on a support portal. 7.1.3 The Service Provider shall respond to all support requests. 7.1.4 The Support Centre shall be available for support requests on Monday to Friday from 08:00 AM – 5:00 PM (each “Business Day”) and on Standby after-hours including weekends and public holidays. 7.1.5 The Support Centre shall be responsible to perform the following functions: 7.1.5.1 Document all support and all logged requests and issue a reference number for each incident. 7.1.5.2 Monitor and manage the resolution of incidents from the initial support request to resolution. 7.1.5.3 Route incidents to the appropriate resource for resolution. 7.1.5.4 Perform problem diagnosis. 7.1.5.5 Answer queries regarding the usage and performance of the system. 7.1.5.6 Access the system remotely for diagnosis and correction of problems. 7.1.5.7 Contact the City Power Representative at regular intervals to provide status and/or resolution of problems. 7.2 CITY POWER’S RESPONSIBILITIES. SHALL BE RESPONSIBLE FOR THE FOLLOWING FUNCTIONS: City Power shall provide 1st line support, which entails the following: 7.2.1 Response to End-user queries regarding the usage or performance of the system. 7.2.2 Resolve system problems with support from the Service Provider where necessary. 7.2.3 Swap defective hardware components using spare parts. 7.2.4 Hand over complex system problems to the Service Provider through the Support Desk. 7.2.5 File a support request with the Support Desk for software and hardware support. 7.2.6 Inform and update the service provider of all information related to the encountered software or hardware problem. 7.3 ON-SITE SUPPORT On-site support shall be the responsibility of the appointed service provider. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26 The service provider shall ensure that at least one qualified support resource is available to conduct physical on-site visits to City Power premises weekly and when required. All on-site support services shall be delivered in accordance with the agreed Service Level Agreement (SLA), including defined response times, resolution targets, and escalation procedures. 7.4 SYSTEM MAINTENANCE 7.4.1 The Service Provider shall perform on-site routine system maintenance once every week, the weekly site visits shall include but not be limited to the following: 7.4.2 General routine checks of the system status. 7.4.3 Resolving system alarms. 7.4.4 Routine tests of the equipment’s performance against the relevant equipment specifications. 7.5 SOFTWARE UPGRADE 7.5.1 The Service Provider shall be responsible for providing software upgrades as may be required to fix bugs, introduce added functionality, and keep the system fully functional. 7.5.2 Upgrades shall be made available either on-premises or via a VPN connection. 7.6 INCIDENT MANAGEMENT PRIORITY AND RESPONSE TIMES TABLE: A PRIORITY LEVEL RATING OF ALL SUPPORT QUERIES IS AS PER THE TABLE BELOW: PRIORITY DESCRIPTION CONDITION 1 Critical Total system failure 2 High Unavailability of major system functionality 3 Medium Unavailability of minor system functionality 4 Low All configurations and minor ad hoc programming on request 5 Configuration and Includes all configurations and minor ad hoc programming on request programming TABLE B: RESPONSE TIMES SHALL BE AS FOLLOWS: PRIORITY RESPONSE TIME COMMENCEMENT FEEDBACK MAXIMUM TIME TO REPAIR 1 1⁄2 HR 1 HR ON SITE 4 HOURS 2 1 HRS 2 HRS ON SITE 5 HOURS 3 2 HRS 3 HRS ON SITE 6 HOURS 4 6 HRS 8 HRS DAILY 12 HOURS 5 24 HRS 36 HRS DAILY 48 HOURS
DOCUMENTATION The Service Provider shall provide all documentation required, including but not limited to manuals, licenses, and catalogues. Documentation shall be in both hard and soft copies. STANDARD FOR ICT CYBER SECURITY REFERENCE REV ENHANCEMENT – NDR Tool CP_TSSTAN_156 1 OF 26
Health & Safety
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)A health and safety system/plan shall be set up to ensure proper management and compliance during
manufacture, installation, removal, transportation, and disposal. Guidance on the requirements of a health
and safety plan shall be found in ISO 45001:2018 standards. The details shall be subject to an agreement
between City Power and the Supplier.
4.3.7 Compliance and Regulatory Reporting
4.3.7.1.1 The solution and its implementation shall comply with the Protection of Personal Information Act,
2013 (POPIA), and the Service Provider shall describe how personal information captured in network
traffic is identified, minimised, masked, protected and lawfully processed.
4.3.7.1.2 The solution shall provide POPIA-aligned reporting, including the evidence required to support
notification of a security compromise to the Information Regulator and to affected data subjects.
4.3.7.1.3 The solution shall provide reporting mapped to ISO/IEC 27001:2022, including the Annex A controls
relevant to monitoring, logging, threat intelligence, network security and information security
incident management, in support of the City Power information security management system.
4.3.7.1.4 The solution shall provide reporting aligned to ISO/IEC 27002:2022 control guidance and to ISO/IEC
27035 information security incident management practice.
4.3.7.1.5 The solution shall provide reporting mapped to the MITRE ATT&CK framework and, where applicable,
to the functions of the NIST Cybersecurity Framework.
4.3.7.1.6 The solution shall provide reporting to support King IV and COBIT governance, risk and assurance
reporting requirements.
manufacture, installation, removal, transportation, and disposal. Guidance on the requirements of a health
and safety plan shall be found in ISO 45001:2018 standards. The details shall be subject to an agreement
between City Power and the Supplier.
Environmental
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)An environmental management system/plan shall be set up to ensure the proper environmental management
and compliance is adhered to during manufacturing, installation, removal, transportation, and disposal.
Guidance on the requirements for an environmental management system shall be found in ISO 14001:2015
standards. The details shall be subject to an agreement between City Power and the Supplier. This is to ensure
that the asset created conforms to environmental standards and City Power SHERQ Policy.
Standard for ICT cyber security reference rev
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
Annexure a – bibliography
None
Standard for ICT cyber security reference rev
ENHANCEMENT – NDR Tool CP_TSSTAN_156 1
Of 26
Annexure b - revision information
Date rev. NO. notes
September 2024 0 First issue
August 2026 1 Second issue
Technical requirements changes and general editing
Foreword ................................................................................................................................................ 3
Introduction .......................................................................................................................................... 4
Scope of work ................................................................................................................................... 4
Normative references ..................................................................................................................... 5
Definitions ......................................................................................................................................... 6
Requirements .................................................................................................................................... 7
Pre-deployment assessment.................................................................................................................... 18
Training ............................................................................................................................................ 22
Support and maintenance ............................................................................................................ 22
Documentation .............................................................................................................................. 23
Quality management .................................................................................................................... 24
Health and safety........................................................................................................................... 24
Environmental management ...................................................................................................... 24
Annexure a – bibliography ................................................................................................................. 25
Annexure b - revision information .................................................................................................. 26
4.3.6.1.1 A complete bill of materials listing all hardware, appliances, sensors, collectors, aggregation devices,
packet brokers, TAPs, optics and transceivers, cabling and mounting hardware.
4.3.6.1.2 Compute requirements for each component, including CPU cores, memory and the hypervisor
platforms and versions supported.
4.3.6.1.3 Storage requirements, including capacity, storage type, IOPS and throughput, together with the basis
of the calculation against the required retention periods.
4.3.6.1.4 Network requirements, including the number, speed and type of interfaces, VLANs, IP addressing,
routing, and the firewall rules and ports required between components.
4.3.6.1.5 Rack space in rack units, power in kilowatts and feed type, redundancy and cooling requirements at
each site.
4.3.6.1.6 Operating system, database and any third-party software required, and confirmation of whether the
associated licences are included in the offer.
4.3.6.1.7 Time synchronisation and DNS requirements, including NTP source and accuracy.
4.3.6.1.8 Certificate, public key infrastructure and directory integration requirements.
4.3.6.1.9 Requirements at each site where sensors are to be deployed, including substations and remote sites.
4.3.6.1.10 Environmental and physical requirements for equipment to be installed in operational or substation
environments, including operating temperature range and ingress protection rating.
4.3.6.1.11 Backup, restore and disaster recovery infrastructure for the solution itself.
4.3.6.1.12 Bandwidth required between sensors, collectors and the analysis platform, and between on-premises
components and any cloud-hosted component.
4.3.6.1.13 Additional infrastructure required to support the stated growth over the contract term.
4.3.6.1.14 Final infrastructure requirements shall be confirmed in the Pre-Assessment Report, and any material
deviation from the tendered bill of materials shall be subject to the prior written approval of City
and compliance is adhered to during manufacturing, installation, removal, transportation, and disposal.
Guidance on the requirements for an environmental management system shall be found in ISO 14001:2015
standards. The details shall be subject to an agreement between City Power and the Supplier. This is to ensure
that the asset created conforms to environmental standards and City Power SHERQ Policy.
Contractual Terms
Source: CP_TSSTAN_224_Rev0_STANDARD FOR ICT Security EnhancementREV2.pdf (unknown)1.1 Solution Acquisition and Implementation
1.1.1 Supply and implementation of an intelligent ICT security solution capable of proactively detecting,
analysing, and responding to cyber threats across the network environment.
1.1.1 Ensure the solution incorporates advanced analytics, artificial intelligence (AI), and machine-learning
capabilities to identify malicious activity, information leakage, and potential attack vectors.
1.2 Threat Detection and Hunting
1.2.1 Implement systems that continuously analyse network events and security logs to detect anomalous
and malicious behaviour.
1.2.2 Provide cyber threat-hunting capabilities that enable proactive identification, investigation,
mitigation, and remediation of security threats.
1.3 Prevention of Cyber Incidents
1.3.1 Ensure the implemented solution effectively prevents malicious attacks, data breaches, and business
disruptions resulting from cyber-attacks.
1.3.2 Strengthen City Power’s overall ICT security posture and resilience against evolving cyber threats.
1.4 Licensing, Support, and Maintenance
1.4.1 Provide all required software licensing for the duration of the contract.
4.2.5.5 The solution shall track and report incident lifecycle metrics, including mean time to detect and
mean time to respond.
4.2.6 Response and Containment
4.2.6.1 The solution shall support both automated and analyst-initiated response actions, including host
isolation, session termination, blocking and quarantine, through integration with NGFW, NAC, EDR
and directory services.
4.2.6.2 The solution shall allow response playbooks to be configured, tested and executed, with approval
gates where required.
4.2.6.3 The solution shall ensure that no automated response action is applied to operational technology or
critical operational systems without explicit prior authorisation by City Power.
4.2.6.4 The solution shall log every response action taken, whether automated or manual, together with the
initiating rule or user and the outcome.
4.2.6.5 The solution shall support safe roll-back of response actions where a detection is subsequently
found to be a false positive.
4.2.7 Reporting and Dashboards
4.2.7.1 The solution shall provide role-based dashboards suitable for executives, ICT management, SOC
analysts and auditors.
4.2.7.2 The solution shall provide scheduled and on-demand reporting in at least PDF, CSV and Excel
formats.
4.2.7.3 The solution shall provide standard reports covering threat activity, incident trends, asset risk,
detection coverage and compliance posture.
4.2.7.4 The solution shall allow custom reports and dashboards to be built and modified by City Power
without vendor intervention or additional cost.
4.2.8 Administration and Access Control
4.2.8.1 The solution shall provide role-based access control with granular permissions, integrated with City
Sets the constitutional standard for fair, equitable, transparent, competitive and cost-effective public procurement.
Relevant because this is a South African public-sector procurement opportunity.
Act 5 of 2000
Covers preferential procurement and preference-point systems used in public tenders.
Relevant because this is a South African public-sector procurement opportunity.
Act 12 of 2004
Supports anti-corruption controls and supplier integrity in procurement processes.
Relevant because this is a South African public-sector procurement opportunity.
Act 28 of 2024
Provides the national framework for public procurement across government.
Relevant because this is a South African public-sector procurement opportunity.
Act 2 of 2000
Supports access to tender records, award decisions and public-sector procurement information.
Relevant because this is a South African public-sector procurement opportunity.
Act 3 of 2000
Supports lawful, reasonable and procedurally fair administrative tender decisions.
Relevant because this is a South African public-sector procurement opportunity.
These rules are linked to the work category, industry, or regulated service area.
Act 85 of 1993
Sets health and safety duties for contractors, employers and service providers working on public-sector sites.
Relevant because this tender appears to involve guarding, access control, CCTV, surveillance, or private security services.
Act 56 of 2001
Relevant where security providers, guards, access control or private security services are required.
Relevant because this tender appears to involve guarding, access control, CCTV, surveillance, or private security services.
Address
Reuven, Johannesburg, 2091, South Africa
Source confidence
High source confidence
Official source
eTenders.gov.za
Documents found
3
Last checked
11 Sept 2026
AI status
Not enhanced
Data conflicts
None detected
This tender has strong source evidence, including source metadata and supporting tender information synced from the government tender portal.
Tenders SA is not the issuing authority. All tenders are automatically synced from the official government tender portal. Always confirm final submission details, closing dates, briefing sessions, eligibility requirements, and documents on the official government portal before applying.
Learn how to submit a winning bid with these related articles
In 2026, Western Cape’s security procurement landscape remains one of the most active in South Africa, with 176 live security tenders signaling strong demand for compliant service providers. For security contractors, PSIRA compliance is non-negotiable—failing to verify company and guard registrations before submission can lead to immediate disqualification. With government buyers prioritizing regulatory adherence, suppliers must adopt a proactive approach to ensure all certifications are current, accurate, and aligned with tender requirements.
How small security companies and BEE-certified guarding firms use Joint Ventures to compete for PSIRA-regulated government security tenders.
How security installation companies, technology integrators, and electronic security providers can win government tenders for CCTV, access control, alarm monitoring, and integrated electronic security systems in South Africa.
As Gauteng’s security tender landscape intensifies in 2026, contractors must navigate a complex compliance environment where a single oversight can disqualify an entire bid. With over 300 active security tenders in the province, regulatory adherence—particularly PSIRA registration—remains the non-negotiable foundation for participation. This guide clarifies the legal obligations, verification processes, and documentation required to ensure your submission meets the strict standards of South African procurement law.
💡 Want more tendering tips and strategies?
Explore Our BlogGet deep intelligence on Security and investigation activities. Unlock full pricing strategies, bid frequency, and historical win rates.